Live data from Hacker News

Israeli firm can steal phone data in seconds

phys.org

21–30 of 120 posts

Re: Israeli firm can steal phone data in seconds

#22

I wonder if they can crack devices that haven't been booted. Many of the newer smartphones encrypt data and require a password on boot.

Too bad Google made the boot password the same as the screen unlock password. Since virtually everyone wants to be able to quickly unlock their phone, this makes security a Hobson's choice.

Re: Israeli firm can steal phone data in seconds

#23
post #16

It will be interesting if Apple went after Cellebrite under the DMCA anti-circumvention clauses. I would laugh if their product became illegal in the United States.

Probably not, it's an Israeli firm.

Pretty much my reasoning too.

Re: Israeli firm can steal phone data in seconds

#24
post #2

"But privacy and rights activists worry such powerful technology can wind up in the wrong hands, leading to abuses." Am I to believe that this firm is the right hands? Or government? Please...all hands are the wrong hands. These vulnerabilities need to be closed. I wouldn't be surprised if the NSA or some other government tentacle was paying them not to make whatever they found known. Gee, I sound paranoid. What am I…

> I wouldn't be surprised if the NSA or some other government tentacle was paying them not to make whatever they found known.

It looks like your are unsure, so let me clarify.

There really are companies whose only business is to find and sell vulnerabilities to states. (Whether it's exclusive is just a matter of negotiations).

Re: Israeli firm can steal phone data in seconds

#25
post #9
post #3

Earlier quoted context omitted.

Actually Cellebrite themselves have been victim of some kind of hack last month and had a load of their internal documents leaked online. So no, if any, this firm is _not_ the right hands.

Any place which hoards 0-days is a prime target. Even if they are considered to be the "right hands", the "wrong hands" could grab those exploits eventually.

When the target holds a lot of $1 million dollar 0-day exploits, the target is worth hacking into.

Re: Israeli firm can steal phone data in seconds

#26
post #22

I wonder if they can crack devices that haven't been booted. Many of the newer smartphones encrypt data and require a password on boot.

Too bad Google made the boot password the same as the screen unlock password. Since virtually everyone wants to be able to quickly unlock their phone, this makes security a Hobson's choice.

Yeah I can see that being the case for the vast majority of users. Also it's a damned shame that Google enforces a limit of 16 characters for the password.

My own password is a random 16 character string.

Re: Israeli firm can steal phone data in seconds

#29
post #11

It goes without saying - don't make this easy for them(or anyone). Use a strong alphanumeric password on your mobile devices. It's annoying and inconvenient until it saves your ass - there is still no "fast" way to crack a password like "My 42nd spaceship had 4 hearts of gold.", but it's not that difficult for your brain to remember. Fingerprint unlock can save you some of the PITA of typing it - just be sure you pow…

Another interesting point they mention is "recovering years long deleted texts." Consider the filesystem your phone uses for volumes it's writing data to and how it (probably just) unlinks files when deleted... [edit] and I should add a 'factory reset' will probably just write a new filesystem table over the old on disk without wiping anything on most devices

What about doing a factory reset, then use the 'encrypt device' option, then doing another factory reset. Would that provide an extra measure?

Unless, of course, the data in it's final state before the final factory reset is un-encrypted.

Re: Israeli firm can steal phone data in seconds

#30
post #22

I wonder if they can crack devices that haven't been booted. Many of the newer smartphones encrypt data and require a password on boot.

Too bad Google made the boot password the same as the screen unlock password. Since virtually everyone wants to be able to quickly unlock their phone, this makes security a Hobson's choice.

Well otherwise the user will most likely forget the separate boot password as phones typically get rebooted once a month or so.
Post reply on HN