Live data from Hacker News

Decrypting the Signal App

cellebrite.com

21–24 of 24 posts

Re: Decrypting the Signal App

#21
post #7

This immediately smells of marketing bullshit: > Decrypting messages and attachments sent with Signal has been all but impossible…until now. > We found that acquiring the key requires reading a value from the shared preferences file and decrypting it using a key called “AndroidSecretKey”, which is saved by an android feature called “Keystore”. Yeah, if you have all the keys you can decrypt stuff.. This is dumb, pleas…

[deleted]

Re: Decrypting the Signal App

#22
post #19

Earlier quoted context omitted.

> Just perhaps not on a $50 Cricket phone with no HSM. On some more expensive devices keys can be obtained from RAM[1]. [1] https://www.cellebrite.com/en/blog/decrypting-databases-usin...

If the keys are in RAM then they aren't in an HSM- they're in RAM (as well as the HSM, but that's irrelevant). More importantly, the app is already unlocked anyway if the keys are in RAM. So that just lets you keep it unlocked. It doesn't help you unlock an app that was locked when you got access to the device.

Indeed. It is still very useful to an investigator who has to examine an unlocked device -- in most corporate investigations this is unlikely to be an issue. Forensic examiners working for the police are likely to have more of a hard time getting codes etc., but they have access to more advanced services[1][2].

[1] https://www.msab.com/2018/12/11/msab-introduces-access-servi... [2] https://www.cellebrite.com/en/advanced-services/

Re: Decrypting the Signal App

#23
post #7

This immediately smells of marketing bullshit: > Decrypting messages and attachments sent with Signal has been all but impossible…until now. > We found that acquiring the key requires reading a value from the shared preferences file and decrypting it using a key called “AndroidSecretKey”, which is saved by an android feature called “Keystore”. Yeah, if you have all the keys you can decrypt stuff.. This is dumb, pleas…

So is the goal here to basically root the android / iphone, then grab the encryption key, then grab the decrypted signal app data, then grab the encryption key? I mean makes sense as a tool if they can automate that well.

Re: Decrypting the Signal App

#24
post #16
post #7

This immediately smells of marketing bullshit: > Decrypting messages and attachments sent with Signal has been all but impossible…until now. > We found that acquiring the key requires reading a value from the shared preferences file and decrypting it using a key called “AndroidSecretKey”, which is saved by an android feature called “Keystore”. Yeah, if you have all the keys you can decrypt stuff.. This is dumb, pleas…

> Yeah, if you have all the keys you can decrypt stuff.. I expect the intended audience for this article is digital forensics examiners, who might be employed by say law enforcement or corporate investigators. Not the average Hacker News crowd.

Signal has considered this by adding an additional client-side "encrypted my messages" locally. So I'm curious if this is what they are referring to.

Post-physical unlocked HD access to the device, aka digital forensics.

Post reply on HN