DOJ says it could make Apple turn over iOS source code and signature if it doesn't cooperate with court order, citing Lavabit case as precedent
FBI ‘could force Apple to hand over private key’ — A legal filing implies that Department of Justice has a plan B, which involves demanding the company's electronic signature
Context & Ripple Effects
This filing escalates the standoff that began when the DoJ filed its motion to compel Apple to help the FBI unlock the San Bernardino shooter's iPhone. In the weeks since, the Justice Department has widened the front, pursuing orders to extract data from roughly a dozen other iPhones in non-terrorism cases, while Apple executives have argued that new iPhones are just as exposed to the requested 'back door'.
What changes today is the threat model: rather than only ordering Apple to write unlocking code, the DOJ now signals it could demand the iOS source code itself plus Apple's private signing key, invoking the Lavabit case — where a provider was compelled to surrender its own keys — as precedent. A same-day filing accuses Apple of deliberately raising technical barriers, and Apple has until March 15 to respond.
First-order effects
- Apple faces a starker choice than drafting one-off code: defiance could trigger an order to hand over the source code and electronic signature that authenticate all iOS updates, turning a single-phone dispute into control over the platform's trust chain.
- The FBI gains immediate leverage in the San Bernardino case without waiting for Congress, since the Lavabit citation gives the court a domestic precedent for compelling key disclosure.
Second-order effects
- The roughly dozen other iPhone extraction orders the Justice Department is pursuing would inherit whatever legal footing this case establishes, converting one contested warrant into a reusable template across ordinary criminal cases.
- If compelled-signing-key disclosure is seen as viable, other encrypted-service providers face the same demand curve Lavabit did — surrender keys or shut down — pushing vendors toward architectures where they hold no such key at all.
Third-order effects
- If the pattern holds, litigation — not legislation — becomes the mechanism that defines the limits of lawful access, with each court ruling setting de facto encryption policy for every device maker and messaging provider.
- Device vendors' incentive shifts structurally toward designs that minimize what can be compelled from them, since the DOJ's own filing demonstrates that holding a master signing capability is itself a legal liability.
The trend: Law-enforcement demands on tech companies are escalating from assistance orders to compelled disclosure of source code and signing keys, making the courts the decisive arena for encryption policy.