Cellebrite doesn't even have a bug bounty programme or contact to report their bugs. Last year I've managed to gain partial access to one of their systems and it took me weeks emailing their internal email addresses to finally fix the bug. They were total ass about it. Now I've got complete access to their entire database and I don't know what do. Can HN advise?
Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer
231–240 of 352 posts
Re: Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer
#232Truly a jaw dropping blog post, as the top comment currently states, Apple may be legally required to at the very least, comment on this situation.
This, if Apple does pursue it, is a copyright matter, not trademark.
Re: Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer
#233To be fair, this vulnerability disclosure is worthless, because it wasn’t actually disclosed—the true vulnerability is purported to be in the file that Signal uses to execute arbitrary code, of which the details are not shared. We are relying on pure trust that the video demonstration of the purported vulnerability is not a forgery. Additionally, I see from the video that the purported vulnerability is present in UFE…
Many vulnerabilities are disclosed without simultaneous disclosure of the PoC. That doesn't make it worthless. Also, not disclosing specifics is reasonable here, given that the vendor is themselves known for using, hoarding, and selling access to 0days. There is no obligation for a researcher to share their research with such a corrupt vendor.
As it stands, the vulnerability is not reproducible by anyone other than Signal. Reproducibility is key in the scientific method and in the court of law.
Re: Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer
#234So I wonder, why disclose this? This will just prompt Cellebrite to improve its security process and sandbox the entire tool. If they wanted to destroy the credibility of the tool, using the vulnerabilities to silently tamper with the collected data or even leaking it online would be a much better option and hit them without any warning, not only jeopardizing those cases but forever casting doubt on not just Cellebri…
Probably disclosure is the best option. Silently tamper with the data might cross a legal line. doing this might put at risk current or past cases where there is a legitimate reason to use this sort of tool. Privacy can be hard. While i 100% defend everybody has the right to privacy, i can also see the need for the capability to break it. Maybe the answer for this is a very tight regulation around the uses of this ki…
i've always wondered if there could be a cryptographic solution to this. issuing decryption keys to governments seems rife for abuse, but some sort of multi-party situation where governmental and non-governmental entities have to cooperate (with actual multiparty key material) to perform a decryption authorized by warrants- with said non-governmental agencies acting as a check on usage of those warrants, their frequency and the eventual publication of their usage could be an interesting approach.
personally i think strong encryption should be a requirement for digital evidence, but even that can be forged.
strange times we live in.
Re: Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer
#235"We have strict licensing policies that govern how customers are permitted to use our technology and do not sell to countries under sanction by the US, Israel or the broader international community."
And these policies are obviously quite effective at preventing such uses.
[1] https://www.theregister.com/2021/04/21/signal_cellebrite/
Re: Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer
#236This is something I have personally looked at as an owner of a UFED touch device (1st gen). By default your software runs in a non-priviledged account but who's to say one of files isn't just straight up being read by FFMPEG and adding or removing evidence from the final report. The official Cellebrite policy has always been "don't worry, if you get stuck, we can send you an expert to testify to the reliability of th…
This purported vulnerability does not rely on FFmpeg, hence the disclaimer.
Re: Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer
#237> By a truly unbelievable coincidence, I was recently out for a walk when I saw a small package fall off a truck ahead of me. As I got closer, the dull enterprise typeface slowly came into focus: Cellebrite. Inside, we found the latest versions of the Cellebrite software, a hardware dongle designed to prevent piracy (tells you something about their customers I guess!), and a bizarrely large number of cable adapters.…
Re: Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer
#238Wow, that video made my day. This bit is key: > "For example, by including a specially formatted but otherwise innocuous file in an app on a device that is then scanned by Cellebrite, it’s possible to execute code that modifies not just the Cellebrite report being created in that scan, but also all previous and future generated Cellebrite reports from all previously scanned devices and all future scanned devices in a…
The video made my inner child feel truly vindicated with my choice of username.
Re: Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer
#239Re: Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer
#240Earlier quoted context omitted.
Eh, this goes two ways. Cellebrite is rarely going to result in the only meaningful evidence that proves a single element of the offense. Instead, it is often used to further an investigation in order to find evidence that is more damning and of a higher evidentiary value. Fortunately for law enforcement, the integrity of the Cellebrite-obtained data is all that important if it leads to further evidence that is more…
I don’t think that’s true. There’s a legal idea of “fruit of the poisonous tree”[0] that basically says you can’t use bad evidence, either in court or as an excuse to collect more, valid evidence. The defense attorney would say “if it hadn’t been for that completely untrustworthy Cellebrite evidence, the police wouldn’t have been able to get that search warrant they used to find the gun at his house, so we want that…
I think the police have been using "parallel construction" to get around that for some time.
https://en.wikipedia.org/wiki/Parallel_construction
> Parallel construction is a law enforcement process of building a parallel, or separate, evidentiary basis for a criminal investigation in order to conceal how an investigation actually began.[1]
> In the US, a particular form is evidence laundering, where one police officer obtains evidence via means that are in violation of the Fourth Amendment's protection against unreasonable searches and seizures, and then passes it on to another officer, who builds on it and gets it accepted by the court under the good-faith exception as applied to the second officer.[2] This practice gained support after the Supreme Court's 2009 Herring v. United States decision.