• Home
  • Latest
  • Fortune 500
  • Finance
  • Tech
  • Leadership
  • Lifestyle
  • Rankings
  • Multimedia

Apple, Jacob Appelbaum and the National Security Agency

By
Philip Elmer-DeWitt
Philip Elmer-DeWitt
Down Arrow Button Icon
By
Philip Elmer-DeWitt
Philip Elmer-DeWitt
Down Arrow Button Icon
December 31, 2013, 5:23 PM ET

Appelbaum at the Chaos Communications Congress: Did Apple know?

FORTUNE — If it weren’t for the Apple (AAPL) angle, I’m not sure I would have watched the entire YouTube video Jacob Appelbaum posted Monday of his hour-long lecture at a hackers conference in Hamburg last weekend.

I’m glad I did, although I’m still not sure what to make of it.

Applebaum is a private security expert with connections to Edward Snowden and Julian Assange and a long history with U.S. intelligence agencies. According to his Wikipedia entry, he has been detained a dozen times and had his laptop and several mobile phones seized — which helps explain the video’s undercurrent of wounded outrage.

Appelbaum was one of the co-authors of Sunday’s big expose on the NSA in Der Spiegel. His particular expertise is the top-secret document from 2008 that provided most of the magazine’s revelations: A 50-page “catalog” of NSA capabilities — some still under development five years ago, some already deployed. They include:


DROPOUTJEEP. Click to enlarge.
  • CANDYGRAM: A telephone tripwire that mimics a cellphone tower.
  • COTTONMOUTH: A modified USB plug for intercepting communications, installing trojans etc.
  • WATERWITCH: A handheld “finishing tool” for finding the exact location of nearby handsets.
  • SURLYSPAWN: Monitors keystrokes when a target computer isn’t connected to the Internet.
  • FOXACID: A system for installing spyware with a “quantum insert” that infects spyware at the packet level.
  • IRONCHEF: Infects networks by installing itself in a computer’s input-output BIOS.
  • JETPLOW: A firmware implant that provides a permanent backdoor through a Cisco (CSCO) firewall.
  • HEADWATER: Does the same for China’s Huawai routers.
  • RAGEMASTER: Taps the line between a desktop computer’s video card and its monitor.
  • HOWLERMONKEY: A radio transceiver for extracting data from systems or making them remote-controllable.
  • MONKEYCALENDAR: Attack software that sends a mobile phone’s location by covert text message.
  • DIETYBOUNCE: Installs a secret payload in a Dell (DELL) computer by reflashing the motherboard BIOS when the machine is turned on.
  • NIGHTSTAND: A mobile system for wirelessly installing exploits of Microsoft (MSFT) Windows from up to eight miles away.
  • SOMBERKNAVE: A Windows XP implant to connect computers to NSA headquarters, from where they can be remotely controlled.
  • ANGRYMONK: Inserts itself into the firmware of hard drives made by Western Digital (WDC), Seagate (STX), Maxtor and Samsung.
  • SWAP: Reflashes the BIOS of multiprocessor systems running Windows, Solaris, Linux or FreeBSD.
  • SPARROW II: A tool for detecting and mapping wireless networks via drone.
  • TOTEGHOSTLY: An implant that allows full remote control of Window Mobile phones.
  • DROPOUTJEEP: (I quote) “A software implant for the Apple iPhone that utilizes modular mission applications to provide specific SIGINT functionality. This functionality includes the ability to remotely push/pull files from the device. SMS retrieval, contact list retrieval, voicemail, geolocation, hot mic, camera capture, cell tower location, etc. Command, control and data exfiltration can occur over SMS messaging or a GPRS data connection. All communications with the implant will be covert and encrypted.”

Appelbaum found references to a long list of U.S. companies whose gear the NSA targeted — including the agency’s favorite phishing holes: Yahoo! (YHOO) and Time Warner’s (TWX) CNN.com.

But it was the last item, DROPOUTJEEP, the only exploit out of 50 that specifically targeted at an Apple product, that became every editor’s favorite second-day story. By Tuesday morning Techmeme had assembled more than 30 headlines about DROPOUTJEEP and made the Daily Dot’s The NSA has nearly complete backdoor access to Apple’s iPhone its lead story.

I don’t mind. If more Americans watch Appelbaum’s video because an Apple headline drew them in, so much the better.

For the record, there’s no evidence that DROPOUTJEEP was ever deployed (it was marked “under development” in 2007), or that Apple knew anything about it.

But Appelbaum seems to think it was, and that Apple did. Here, for the record, is how he put it:

“Do you think Apple helped them build that? I don’t know. I hope Apple will clarify that. Here’s the problem: I don’t really believe that Apple didn’t help them, I can’t really prove it but [the NSA] literally claim that anytime they target an iOS device that it will succeed for implantation. Either they have a huge collection of exploits that work against Apple products, meaning that they are hoarding information about critical systems that American companies produce and sabotaging them, or Apple sabotaged it themselves. Not sure which one it is. I’d like to believe that since Apple didn’t join the PRISM program until after Steve Jobs died, that maybe it’s just that they write shitty software. We know that’s true.”

UPDATE: Apple on Tuesday denied working with the NSA. The official statement, via AllThingsD:

“Apple has never worked with the NSA to create a backdoor in any of our products, including iPhone. Additionally, we have been unaware of this alleged NSA program targeting our products. We care deeply about our customers’ privacy and security. Our team is continuously working to make our products even more secure, and we make it easy for customers to keep their software up to date with the latest advancements. Whenever we hear about attempts to undermine Apple’s industry-leading security, we thoroughly investigate and take appropriate steps to protect our customers. We will continue to use our resources to stay ahead of malicious hackers and defend our customers from security attacks, regardless of who’s behind them.”

Below, while it’s still available, Appelbaum’s full video.

http://youtu.be/b0w36GAyZIA

About the Author
By Philip Elmer-DeWitt
See full bioRight Arrow Button Icon

Latest in

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025

Most Popular

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Fortune Secondary Logo
Rankings
  • 100 Best Companies
  • Fortune 500
  • Global 500
  • Fortune 500 Europe
  • Most Powerful Women
  • World's Most Admired Companies
  • See All Rankings
  • Lists Calendar
Sections
  • Finance
  • Fortune Crypto
  • Features
  • Leadership
  • Health
  • Commentary
  • Success
  • Retail
  • Mpw
  • Tech
  • Lifestyle
  • CEO Initiative
  • Asia
  • Politics
  • Conferences
  • Europe
  • Newsletters
  • Personal Finance
  • Environment
  • Magazine
  • Education
Customer Support
  • Frequently Asked Questions
  • Customer Service Portal
  • Privacy Policy
  • Terms Of Use
  • Single Issues For Purchase
  • International Print
Commercial Services
  • Advertising
  • Fortune Brand Studio
  • Fortune Analytics
  • Fortune Conferences
  • Business Development
  • Group Subscriptions
About Us
  • About Us
  • Press Center
  • Work At Fortune
  • Terms And Conditions
  • Site Map
  • About Us
  • Press Center
  • Work At Fortune
  • Terms And Conditions
  • Site Map
  • Facebook icon
  • Twitter icon
  • LinkedIn icon
  • Instagram icon
  • Pinterest icon

Latest in

America’s data centers are thirsty. Rural towns are paying the price—from tanked water pressure to stolen desert groundwater
EnvironmentAmazon
America’s data centers are thirsty. Rural towns are paying the price—from tanked water pressure to stolen desert groundwater
By Catherina GioinoMay 13, 2026
1 hour ago
geezer
North AmericaAnimals
Debbie Gibson, Geezer Butler of Black Sabbath want you to adopt a beagle rescued from an experimental lab in Wisconsin
By Scott Bauer and The Associated PressMay 13, 2026
3 hours ago
spencer
PoliticsElections
Los Angeles may have its own Zohran in the form of ex-reality star Spencer Pratt
By Jonathan J. Cooper and The Associated PressMay 13, 2026
3 hours ago
charles
PoliticsUnited Kingdom
King Charles lays out government agenda as Starmer fights for survival: ‘absolutely preposterous’
By Pan Pylas, Danica Kirka and The Associated PressMay 13, 2026
3 hours ago
After nearly a year of delays, Trump Mobile’s CEO says the gold-plated Trump phone will begin shipping to buyers this week
North AmericaDonald Trump
After nearly a year of delays, Trump Mobile’s CEO says the gold-plated Trump phone will begin shipping to buyers this week
By Marco Quiroz-GutierrezMay 13, 2026
3 hours ago
malaysia
EnergyIran
Malaysia is shocked, shocked to find Iranian-linked tankers slipping through its waters
By Eileen Ng and The Associated PressMay 13, 2026
3 hours ago

Most Popular

The Bezos family just donated $100 million to help achieve one of Mayor Zohran Mamdani’s top campaign promises
Politics
The Bezos family just donated $100 million to help achieve one of Mayor Zohran Mamdani’s top campaign promises
By Jake AngeloMay 12, 2026
1 day ago
Nearly 50,000 Lake Tahoe residents have to find a new power source after their energy source looks to redirect lines to data centers
Travel & Leisure
Nearly 50,000 Lake Tahoe residents have to find a new power source after their energy source looks to redirect lines to data centers
By Catherina GioinoMay 12, 2026
1 day ago
It’s not just Canadian tourists snubbing U.S. cities. Business leaders are cancelling more trips to America as geopolitical tensions continue
North America
It’s not just Canadian tourists snubbing U.S. cities. Business leaders are cancelling more trips to America as geopolitical tensions continue
By Sasha RogelbergMay 12, 2026
1 day ago
Anthropic’s Daniela Amodei says entrepreneurs should go on vacation to road test potential cofounders—if they’re a drain, they’re ‘the wrong choice’
Success
Anthropic’s Daniela Amodei says entrepreneurs should go on vacation to road test potential cofounders—if they’re a drain, they’re ‘the wrong choice’
By Emma BurleighMay 12, 2026
1 day ago
Forget U.S. debt, China's total borrowing is in 'a league of its own'—much worse and deteriorating faster, analyst says
Economy
Forget U.S. debt, China's total borrowing is in 'a league of its own'—much worse and deteriorating faster, analyst says
By Jason MaMay 11, 2026
2 days ago
U.S. hotels are calling the World Cup a 'non-event' and 80% warn bookings are falling short of expectations, report finds
North America
U.S. hotels are calling the World Cup a 'non-event' and 80% warn bookings are falling short of expectations, report finds
By Sasha RogelbergMay 12, 2026
2 days ago

© 2026 Fortune Media IP Limited. All Rights Reserved. Use of this site constitutes acceptance of our Terms of Use and Privacy Policy | CA Notice at Collection and Privacy Notice | Do Not Sell/Share My Personal Information
FORTUNE is a trademark of Fortune Media IP Limited, registered in the U.S. and other countries. FORTUNE may receive compensation for some links to products and services on this website. Offers may be subject to change without notice.