to an alleged terrorist shooter in San Bernardino, California.82 The suit was eventually
dropped after an unidentified third party successfully cracked the 5C iPhone running iOS 9
software, at a cost of US$1.3 million to the FBI.83
This situation demonstrates the diversity of efforts required for combatting cybercrime,
and is anecdotal of the technical limitations on a government’s ability to access data to
investigate and prosecute acts of terrorism or cybercrime without the input of the private
sector. The case raised the debate over whether private technology companies’ encryption
technologies protect privacy or endanger the public by preventing law enforcement access
to critical information. As cyberspace continues to evolve, innovated investigative tools will
also correspondingly be required to enable effective law enforcement investigations. While
this particular standoff has come to an end, the tension between a government’s desire
to access technology and data necessary to enable effective investigation and the private
sector’s legitimate interest in providing secure technology and services to consumers as well
as protecting proprietary investments has not. Moreover, while this suit was dropped, the
US Government has since initiated other proceedings to compel Apple to assist the FBI in
unlocking an iPhone 5s running iOS 7, though this time involving a “routine drug case”.84
This incident also demonstrates that perfectly legitimate products—in this case, an iPhone—
have become central to committing cybercrimes. Such technology, although only incidentally
being used to support criminal activity, is being developed by a multitude of private actors.
The government’s ability to cover the great diversity of fields and spaces is well-beyond
present budgetary constraints, illustrating the necessity of public-private cooperation. The
public-private problem is only likely to grow, as not only Apple85 but other technology firms,
such as WhatsApp,86 extend security and protection with end-to-end encryption (E2EE) and
other security measures.
Indeed, following the 2017 terrorist attack outside the UK Houses of Parliament in London in
March, and again following those in Manchester in June, UK authorities recently advocated
that similar access should be granted vis-à-vis instant-messaging services, most notably for
WhatsApp.87 While the UK Home Secretary has sought to enlist the support of technology
and social media at large,88 the UK Prime Minister having repeated as much,89 it seems
unlikely that, even with private-sector cooperation, the problem would ever be resolved:
simply put, the technological ease of encrypting communications means that a rival app or
process is likely to appear almost immediately should present instant messaging systems
be obliged to create such a “back door” for government. Moreover, lowered technological
barriers to entry are bolstered by market demand, which, for numerous reasons—many
of which are legitimate and legal—incentivizes the development of secure, anonymous
communication tools.
Creating a strong legal cybersecurity framework is complex. The fundamentals of doing so
range from establishing strong legal foundations and a comprehensive and regularly updated
cybersecurity strategy, to engendering trust, working in partnership and promoting cybersecurity
Page 24 | Chapter 1 | § B. Phenomenon & Dimensions of Cybercrime
Table of Contents