• Home
  • Latest
  • Fortune 500
  • Finance
  • Tech
  • Leadership
  • Lifestyle
  • Rankings
  • Multimedia

Apple, Jacob Appelbaum and the National Security Agency

By
Philip Elmer-DeWitt
Philip Elmer-DeWitt
Down Arrow Button Icon
By
Philip Elmer-DeWitt
Philip Elmer-DeWitt
Down Arrow Button Icon
December 31, 2013, 5:23 PM ET

Appelbaum at the Chaos Communications Congress: Did Apple know?

FORTUNE — If it weren’t for the Apple (AAPL) angle, I’m not sure I would have watched the entire YouTube video Jacob Appelbaum posted Monday of his hour-long lecture at a hackers conference in Hamburg last weekend.

I’m glad I did, although I’m still not sure what to make of it.

Applebaum is a private security expert with connections to Edward Snowden and Julian Assange and a long history with U.S. intelligence agencies. According to his Wikipedia entry, he has been detained a dozen times and had his laptop and several mobile phones seized — which helps explain the video’s undercurrent of wounded outrage.

Appelbaum was one of the co-authors of Sunday’s big expose on the NSA in Der Spiegel. His particular expertise is the top-secret document from 2008 that provided most of the magazine’s revelations: A 50-page “catalog” of NSA capabilities — some still under development five years ago, some already deployed. They include:


DROPOUTJEEP. Click to enlarge.
  • CANDYGRAM: A telephone tripwire that mimics a cellphone tower.
  • COTTONMOUTH: A modified USB plug for intercepting communications, installing trojans etc.
  • WATERWITCH: A handheld “finishing tool” for finding the exact location of nearby handsets.
  • SURLYSPAWN: Monitors keystrokes when a target computer isn’t connected to the Internet.
  • FOXACID: A system for installing spyware with a “quantum insert” that infects spyware at the packet level.
  • IRONCHEF: Infects networks by installing itself in a computer’s input-output BIOS.
  • JETPLOW: A firmware implant that provides a permanent backdoor through a Cisco (CSCO) firewall.
  • HEADWATER: Does the same for China’s Huawai routers.
  • RAGEMASTER: Taps the line between a desktop computer’s video card and its monitor.
  • HOWLERMONKEY: A radio transceiver for extracting data from systems or making them remote-controllable.
  • MONKEYCALENDAR: Attack software that sends a mobile phone’s location by covert text message.
  • DIETYBOUNCE: Installs a secret payload in a Dell (DELL) computer by reflashing the motherboard BIOS when the machine is turned on.
  • NIGHTSTAND: A mobile system for wirelessly installing exploits of Microsoft (MSFT) Windows from up to eight miles away.
  • SOMBERKNAVE: A Windows XP implant to connect computers to NSA headquarters, from where they can be remotely controlled.
  • ANGRYMONK: Inserts itself into the firmware of hard drives made by Western Digital (WDC), Seagate (STX), Maxtor and Samsung.
  • SWAP: Reflashes the BIOS of multiprocessor systems running Windows, Solaris, Linux or FreeBSD.
  • SPARROW II: A tool for detecting and mapping wireless networks via drone.
  • TOTEGHOSTLY: An implant that allows full remote control of Window Mobile phones.
  • DROPOUTJEEP: (I quote) “A software implant for the Apple iPhone that utilizes modular mission applications to provide specific SIGINT functionality. This functionality includes the ability to remotely push/pull files from the device. SMS retrieval, contact list retrieval, voicemail, geolocation, hot mic, camera capture, cell tower location, etc. Command, control and data exfiltration can occur over SMS messaging or a GPRS data connection. All communications with the implant will be covert and encrypted.”

Appelbaum found references to a long list of U.S. companies whose gear the NSA targeted — including the agency’s favorite phishing holes: Yahoo! (YHOO) and Time Warner’s (TWX) CNN.com.

But it was the last item, DROPOUTJEEP, the only exploit out of 50 that specifically targeted at an Apple product, that became every editor’s favorite second-day story. By Tuesday morning Techmeme had assembled more than 30 headlines about DROPOUTJEEP and made the Daily Dot’s The NSA has nearly complete backdoor access to Apple’s iPhone its lead story.

I don’t mind. If more Americans watch Appelbaum’s video because an Apple headline drew them in, so much the better.

For the record, there’s no evidence that DROPOUTJEEP was ever deployed (it was marked “under development” in 2007), or that Apple knew anything about it.

But Appelbaum seems to think it was, and that Apple did. Here, for the record, is how he put it:

“Do you think Apple helped them build that? I don’t know. I hope Apple will clarify that. Here’s the problem: I don’t really believe that Apple didn’t help them, I can’t really prove it but [the NSA] literally claim that anytime they target an iOS device that it will succeed for implantation. Either they have a huge collection of exploits that work against Apple products, meaning that they are hoarding information about critical systems that American companies produce and sabotaging them, or Apple sabotaged it themselves. Not sure which one it is. I’d like to believe that since Apple didn’t join the PRISM program until after Steve Jobs died, that maybe it’s just that they write shitty software. We know that’s true.”

UPDATE: Apple on Tuesday denied working with the NSA. The official statement, via AllThingsD:

“Apple has never worked with the NSA to create a backdoor in any of our products, including iPhone. Additionally, we have been unaware of this alleged NSA program targeting our products. We care deeply about our customers’ privacy and security. Our team is continuously working to make our products even more secure, and we make it easy for customers to keep their software up to date with the latest advancements. Whenever we hear about attempts to undermine Apple’s industry-leading security, we thoroughly investigate and take appropriate steps to protect our customers. We will continue to use our resources to stay ahead of malicious hackers and defend our customers from security attacks, regardless of who’s behind them.”

Below, while it’s still available, Appelbaum’s full video.

http://youtu.be/b0w36GAyZIA

About the Author
By Philip Elmer-DeWitt
See full bioRight Arrow Button Icon

Latest in

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025

Most Popular

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Fortune Secondary Logo
Rankings
  • 100 Best Companies
  • Fortune 500
  • Global 500
  • Fortune 500 Europe
  • Most Powerful Women
  • Future 50
  • World’s Most Admired Companies
  • See All Rankings
Sections
  • Finance
  • Fortune Crypto
  • Features
  • Leadership
  • Health
  • Commentary
  • Success
  • Retail
  • Mpw
  • Tech
  • Lifestyle
  • CEO Initiative
  • Asia
  • Politics
  • Conferences
  • Europe
  • Newsletters
  • Personal Finance
  • Environment
  • Magazine
  • Education
Customer Support
  • Frequently Asked Questions
  • Customer Service Portal
  • Privacy Policy
  • Terms Of Use
  • Single Issues For Purchase
  • International Print
Commercial Services
  • Advertising
  • Fortune Brand Studio
  • Fortune Analytics
  • Fortune Conferences
  • Business Development
  • Group Subscriptions
About Us
  • About Us
  • Editorial Calendar
  • Press Center
  • Work At Fortune
  • Diversity And Inclusion
  • Terms And Conditions
  • Site Map
Fortune Secondary Logo
  • About Us
  • Editorial Calendar
  • Press Center
  • Work At Fortune
  • Diversity And Inclusion
  • Terms And Conditions
  • Site Map
  • Facebook icon
  • Twitter icon
  • LinkedIn icon
  • Instagram icon
  • Pinterest icon

Latest in

EnergyOil
The Strait of Hormuz is a critical choke point for global energy markets, but there are ways to get around it
By Jason MaMarch 2, 2026
4 hours ago
trump
Economynational debt
Interest on the $38.8 trillion national debt has tripled since 2020, and it already costs taxpayers more than defense and Medicaid
By Nick LichtenbergMarch 2, 2026
5 hours ago
trump
Middle EastMiddle East
Trump’s strikes on Iran could cost American economy as much as $210 billion, top budget expert says
By Nick LichtenbergMarch 2, 2026
5 hours ago
OpenAI logo is seen in this photo illustration with the South Korean flag in the background
AIOpenAI
‘Could it kill someone?’ A Seoul woman allegedly used ChatGPT to carry out two murders in South Korean motels
By Catherina GioinoMarch 2, 2026
5 hours ago
Commercial vessels in the Persian Gulf
EnergyIran
Energy markets offer ‘relatively small reaction’ to Iran war, but prices could spike if oil and gas aren’t flowing by the end of the week
By Jordan BlumMarch 2, 2026
5 hours ago
A woman stands with her hand on her hip as she pumps gas into her car.
EnergyOil
Oil markets are bracing for $100 barrels and a redux of a 1970s-era crisis but ‘three times the scale,’ analyst warns
By Sasha RogelbergMarch 2, 2026
5 hours ago

Most Popular

placeholder alt text
Middle East
U.S. military gives Iran a taste of its own medicine with cheap copycat Shahed drones, while concern shifts to munitions supply in extended conflict
By Jason MaMarch 1, 2026
1 day ago
placeholder alt text
Success
MacKenzie Scott's close relationship with Toni Morrison long before Amazon put Scott on the path to give more than $1 billion to HBCUs
By Sasha RogelbergMarch 1, 2026
1 day ago
placeholder alt text
Economy
Your grandparents are the reason the U.S. isn't in a recession right now. That won't last forever
By Eleanor PringleMarch 1, 2026
2 days ago
placeholder alt text
AI
American schools weren’t broken until Silicon Valley used a lie to convince them they were—now reading and math scores are plummeting
By Sasha RogelbergMarch 1, 2026
1 day ago
placeholder alt text
Health
Gen Z men are eating ‘boy kibble,’ the human equivalent to dog food, to load up on protein cheaply
By Jake AngeloMarch 1, 2026
2 days ago
placeholder alt text
Success
Slack cofounder says workers and CEOs can get stuck doing 'fake' work like pre-meetings and slideshows
By Emma BurleighMarch 1, 2026
1 day ago

© 2026 Fortune Media IP Limited. All Rights Reserved. Use of this site constitutes acceptance of our Terms of Use and Privacy Policy | CA Notice at Collection and Privacy Notice | Do Not Sell/Share My Personal Information
FORTUNE is a trademark of Fortune Media IP Limited, registered in the U.S. and other countries. FORTUNE may receive compensation for some links to products and services on this website. Offers may be subject to change without notice.