FBI does not have to reveal the name of a vendor that unlocked San Bernardino shooter's iPhone, judge rules in FOIA lawsuit filed by Vice, USA Today, and AP
A federal judge has ruled that the FBI does not have to make public how much it paid last year to unlock an iPhone used …
Context & Ripple Effects
The arc here runs back to April 2016, when sources reported the FBI paid hackers for an undisclosed software flaw rather than using Cellebrite, and later paid under $1M for a technique reusable on any iPhone 5c running iOS 9. The bureau also declined to send the method through a government review that could have forced it to share details with Apple — keeping the capability entirely outside public view.
First-order effects
- AP, Vice Media, and Gannett — who sued the FBI in September 2016 under FOIA — lose this round: neither the vendor's identity nor the price becomes public, and the FBI's gray-hat procurement stays shielded from disclosure.
Second-order effects
- With judicial cover established, outside hackers and firms face lower risk of exposure when selling unlock techniques to the FBI, strengthening the bureau's access to an already-opaque exploit market while leaving Apple with no channel to learn about flaws in its own devices.
Third-order effects
- If law-enforcement agencies can routinely classify purchased hacking capabilities beyond FOIA's reach, government exploit acquisition hardens into a parallel market that answers to neither the public nor the vendors whose products are broken — a structure regulators and device makers have little leverage over.
The trend: Government hacking is consolidating into a buy-don't-build procurement model whose vendors, prices, and methods sit increasingly outside public accountability.