to an alleged terrorist shooter in San Bernardino, California.82 The suit was eventually dropped after an unidentified third party successfully cracked the 5C iPhone running iOS 9 software, at a cost of US$1.3 million to the FBI.83 This situation demonstrates the diversity of efforts required for combatting cybercrime, and is anecdotal of the technical limitations on a government’s ability to access data to investigate and prosecute acts of terrorism or cybercrime without the input of the private sector. The case raised the debate over whether private technology companies’ encryption technologies protect privacy or endanger the public by preventing law enforcement access to critical information. As cyberspace continues to evolve, innovated investigative tools will also correspondingly be required to enable effective law enforcement investigations. While this particular standoff has come to an end, the tension between a government’s desire to access technology and data necessary to enable effective investigation and the private sector’s legitimate interest in providing secure technology and services to consumers as well as protecting proprietary investments has not. Moreover, while this suit was dropped, the US Government has since initiated other proceedings to compel Apple to assist the FBI in unlocking an iPhone 5s running iOS 7, though this time involving a “routine drug case”.84 This incident also demonstrates that perfectly legitimate products—in this case, an iPhone— have become central to committing cybercrimes. Such technology, although only incidentally being used to support criminal activity, is being developed by a multitude of private actors. The government’s ability to cover the great diversity of fields and spaces is well-beyond present budgetary constraints, illustrating the necessity of public-private cooperation. The public-private problem is only likely to grow, as not only Apple85 but other technology firms, such as WhatsApp,86 extend security and protection with end-to-end encryption (E2EE) and other security measures. Indeed, following the 2017 terrorist attack outside the UK Houses of Parliament in London in March, and again following those in Manchester in June, UK authorities recently advocated that similar access should be granted vis-à-vis instant-messaging services, most notably for WhatsApp.87 While the UK Home Secretary has sought to enlist the support of technology and social media at large,88 the UK Prime Minister having repeated as much,89 it seems unlikely that, even with private-sector cooperation, the problem would ever be resolved: simply put, the technological ease of encrypting communications means that a rival app or process is likely to appear almost immediately should present instant messaging systems be obliged to create such a “back door” for government. Moreover, lowered technological barriers to entry are bolstered by market demand, which, for numerous reasons—many of which are legitimate and legal—incentivizes the development of secure, anonymous communication tools. Creating a strong legal cybersecurity framework is complex. The fundamentals of doing so range from establishing strong legal foundations and a comprehensive and regularly updated cybersecurity strategy, to engendering trust, working in partnership and promoting cybersecurity Page 24 | Chapter 1 | § B. Phenomenon & Dimensions of Cybercrime Table of Contents

Select target paragraph3