Live data from Hacker News

Israeli firm can steal phone data in seconds

phys.org

1–10 of 120 posts

Re: Israeli firm can steal phone data in seconds

#2
"But privacy and rights activists worry such powerful technology can wind up in the wrong hands, leading to abuses."

Am I to believe that this firm is the right hands? Or government? Please...all hands are the wrong hands. These vulnerabilities need to be closed. I wouldn't be surprised if the NSA or some other government tentacle was paying them not to make whatever they found known.

Gee, I sound paranoid. What am I thinking, our government would never do that. Oh wait... http://www.reuters.com/article/us-usa-security-rsa-idUSBRE9B...

Re: Israeli firm can steal phone data in seconds

#3
post #2

"But privacy and rights activists worry such powerful technology can wind up in the wrong hands, leading to abuses." Am I to believe that this firm is the right hands? Or government? Please...all hands are the wrong hands. These vulnerabilities need to be closed. I wouldn't be surprised if the NSA or some other government tentacle was paying them not to make whatever they found known. Gee, I sound paranoid. What am I…

Actually Cellebrite themselves have been victim of some kind of hack last month and had a load of their internal documents leaked online. So no, if any, this firm is _not_ the right hands.

Re: Israeli firm can steal phone data in seconds

#4
> Among the data the firm claims to be able to access are text messages deleted years previously.

Among all the claims this one seems like it might be one that holds up with very recent iOS/Android releases. It would be interesting to find out whether they rely solely on the encryption to protect the deleted messages and whether overwriting the data would be thwarted by flash device wear-leveling indirection.

Re: Israeli firm can steal phone data in seconds

#6
So we have learned that some phone vendors give Cellebrite their phones before they reach market in order for them to discover and exploit vulnerabilities. Apple refuses to do business with these 'forensic' criminals.

Do not purchase a phone from a vendor that engages in this unethical practise.

Re: Israeli firm can steal phone data in seconds

#7
It goes without saying - don't make this easy for them(or anyone). Use a strong alphanumeric password on your mobile devices. It's annoying and inconvenient until it saves your ass - there is still no "fast" way to crack a password like "My 42nd spaceship had 4 hearts of gold.", but it's not that difficult for your brain to remember.

Fingerprint unlock can save you some of the PITA of typing it - just be sure you power off your device when you have even the slightest chance of encountering an actor that could seize your mobile device - that way the passphrase will be required.

Re: Israeli firm can steal phone data in seconds

#8
"Could you do anything to deprive them from throwing a stone at someone or from driving a car and running over people?

"You can't blame the car manufacturer at that point for delivering a car that was utilised to commit that kind of crime," he said.

This is specious reasoning. The point of a car is not to run over people; it's to go from point A to point B. This technology, on the other hand, has only one purpose: to break into cellphones.

Re: Israeli firm can steal phone data in seconds

#9
post #3
post #2

"But privacy and rights activists worry such powerful technology can wind up in the wrong hands, leading to abuses." Am I to believe that this firm is the right hands? Or government? Please...all hands are the wrong hands. These vulnerabilities need to be closed. I wouldn't be surprised if the NSA or some other government tentacle was paying them not to make whatever they found known. Gee, I sound paranoid. What am I…

Actually Cellebrite themselves have been victim of some kind of hack last month and had a load of their internal documents leaked online. So no, if any, this firm is _not_ the right hands.

Any place which hoards 0-days is a prime target. Even if they are considered to be the "right hands", the "wrong hands" could grab those exploits eventually.
Post reply on HN