Live data from Hacker News

Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer

signal.org

101–110 of 352 posts

Re: Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer

#101

Earlier quoted context omitted.

Indeed, how convenient . If it truly did fall off the truck right while he is on a walk then there is the possibility that is a rubber duckie attack. This is basically the equivalent of leaving a USB flash drive lying around. I hope the author took the necessary precautions when reverse engineering the device. Companies like cellebrite have deep connections to certain three letter communities that staging this sort o…

"falling off a truck" is slang for "was stolen".

TIL: https://idioms.thefreedictionary.com/fall+off+a+truck

Edit: looking up a bit more, it seems like this idiom is used to denote goods sold for cheap because they were stolen. Like "Bob is selling genuine iPhones very cheap, I fear they fell from the back of a truck".

Edit edit: I initially took it as "we won't tell how we got this", because I didn't know this idiom, but it seems several people agree with this interpretation. Not necessarily stolen, but obtained from an undisclosed source.

Re: Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer

#102

Earlier quoted context omitted.

Signal isn't going to actually do it, they know how that would end, they're just playing the FUD game in the other direction. Which I am 100% on board with.

Maybe the one thing worse than boasting that you're putting malware in your product is boasting about it and not doing it.

They are not putting malware into their app. They are adding athletically pleasing files to their app. Is it Signals fault if someone else's software doesn't work properly with them? How can Signal test every piece of software to make sure it's compatible with their own software? Especially when the other software is using Signal in a unintended way.

It's not signals job to secure 3rd party software, that's entirely on the 3rd party.

Re: Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer

#103
post #85
post #30

Earlier quoted context omitted.

> If it truly did fall of the truck lol

Seeing reactions like GP’s I’m surprised at how many people don’t know this expression.

I thought it was an euphemism because they couldn't reveal who gave it to them. Confessing it was stolen, even as an euphemism, is too blatant to be taken seriously IMO.

Re: Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer

#104
post #7

This is truly a hacker’s retort. It attacks Cellebrite's ability to operate by casting doubt on the reports generated by the product that their customers may wish to use in court. It places them in legal peril from Apple, and removes any cover Apple would have to not take legal action. (I assume someone at Apple knew they were shipping their DLLs?) It makes a thinly-veiled threat that any random Signal user's data ma…

All that trouble becaused a bag conveniently "fell from a truck". All in all I'm really happy for all this.

I found that funny too. It sounds to me like a good way to end up with the device to analyze without being constrained by a contract or EULA prohibiting it.

Re: Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer

#105
post #7

This is truly a hacker’s retort. It attacks Cellebrite's ability to operate by casting doubt on the reports generated by the product that their customers may wish to use in court. It places them in legal peril from Apple, and removes any cover Apple would have to not take legal action. (I assume someone at Apple knew they were shipping their DLLs?) It makes a thinly-veiled threat that any random Signal user's data ma…

Sadly I suspect the people in law enforcement who make purchasing decisions never read the Signal blog, and therefore all these points will be moot.

Re: Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer

#106
post #85
post #30

Earlier quoted context omitted.

> If it truly did fall of the truck lol

Seeing reactions like GP’s I’m surprised at how many people don’t know this expression.

If English is your second language, you may not have come across it. It's a very informal and infrequent idiom.

Re: Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer

#107
post #7

This is truly a hacker’s retort. It attacks Cellebrite's ability to operate by casting doubt on the reports generated by the product that their customers may wish to use in court. It places them in legal peril from Apple, and removes any cover Apple would have to not take legal action. (I assume someone at Apple knew they were shipping their DLLs?) It makes a thinly-veiled threat that any random Signal user's data ma…

Sadly I suspect the people in law enforcement who make purchasing decisions never read the Signal blog, and therefore all these points will be moot.

They don't have to read that.

The defense lawyers have to read it, and the people in law enforcement need to read the cases where judges throw out Cellebrite evidence based on that.

Re: Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer

#108
post #7

This is truly a hacker’s retort. It attacks Cellebrite's ability to operate by casting doubt on the reports generated by the product that their customers may wish to use in court. It places them in legal peril from Apple, and removes any cover Apple would have to not take legal action. (I assume someone at Apple knew they were shipping their DLLs?) It makes a thinly-veiled threat that any random Signal user's data ma…

Sadly I suspect the people in law enforcement who make purchasing decisions never read the Signal blog, and therefore all these points will be moot.

They won't be moot when defense lawyers bring them up.

Re: Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer

#110
post #7

This is truly a hacker’s retort. It attacks Cellebrite's ability to operate by casting doubt on the reports generated by the product that their customers may wish to use in court. It places them in legal peril from Apple, and removes any cover Apple would have to not take legal action. (I assume someone at Apple knew they were shipping their DLLs?) It makes a thinly-veiled threat that any random Signal user's data ma…

It was brazen enough to pop an iTunes GUI a few years back.
Post reply on HN