So I wonder, why disclose this? This will just prompt Cellebrite to improve its security process and sandbox the entire tool. If they wanted to destroy the credibility of the tool, using the vulnerabilities to silently tamper with the collected data or even leaking it online would be a much better option and hit them without any warning, not only jeopardizing those cases but forever casting doubt on not just Cellebri…
The public disclosure about the Apple DLLs could potentially be used to drag Apple into any legal case between somebody versus Cellebrite. The disclosure needs to be public versus private or under seal or whatever to absolve the Cellebrite counterparty of any liability from reverse engineering. Suddenly Apple is now in potential collusion with Cellebrite. Or maybe not. This public disclosure makes the threat of Disco…
Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer
121–130 of 352 posts
Re: Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer
#122Earlier quoted context omitted.
"falling off a truck" is slang for "was stolen".
TIL: https://idioms.thefreedictionary.com/fall+off+a+truck Edit: looking up a bit more, it seems like this idiom is used to denote goods sold for cheap because they were stolen. Like "Bob is selling genuine iPhones very cheap, I fear they fell from the back of a truck". Edit edit: I initially took it as "we won't tell how we got this", because I didn't know this idiom, but it seems several people agree with this inte…
Re: Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer
#123Earlier quoted context omitted.
This still works as written. Just test it yourself with a Mac and Apple Configurator.
I mean, “the iPhone prevents well-behaved software from accessing data without a password” and “software, known to exploit vulnerabilities to get around security features, currently doesn’t have any such exploits” are very different.
Re: Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer
#124> In completely unrelated news, upcoming versions of Signal will be periodically fetching files to place in app storage. These files are never used for anything inside Signal and never interact with Signal software or data, but they look nice, and aesthetics are important in software. I wish I could see those files in action...
Re: Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer
#125Earlier quoted context omitted.
Indeed, how convenient . If it truly did fall off the truck right while he is on a walk then there is the possibility that is a rubber duckie attack. This is basically the equivalent of leaving a USB flash drive lying around. I hope the author took the necessary precautions when reverse engineering the device. Companies like cellebrite have deep connections to certain three letter communities that staging this sort o…
I think we can be relatively confident that the connected machine was airgapped and perhaps run in a VM. Perhaps even in a faraday cage..
One of the screenshots[0] shows the VMware Tools Service running, so yeah, looks like a virtualized guest.
[0]: https://signal.org/blog/images/cellebrite-dlls-loaded.png
Re: Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer
#126That's just hilarious! Nice way of saying we got our hands onto one of these boxes, but we don't want to reveal how. It fell of a truck.
Re: Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer
#127> In completely unrelated news, upcoming versions of Signal will be periodically fetching files to place in app storage. These files are never used for anything inside Signal and never interact with Signal software or data, but they look nice, and aesthetics are important in software. I wish I could see those files in action...
I don't get it, can anyone elaborate on what they are talking about there?
They are basically putting the threat out that if you use Cellebrite on Signal in the future, you might not get the data you expect, and at worst, it may corrupt the report/evidence.
This also brings into question the chain of custody, as an untrusted device being imaged can alter reports of unrelated devices.
Re: Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer
#128Earlier quoted context omitted.
You can't just claim an unknown entity framed you and hope to get anywhere. Heck, you could just as well claim that Cellebrite themselves had it in for you. Cellebrite has never claimed any particular exploits in Signal. Signal is exploitable in this particular way for entirely obvious and common reasons.
It's about casting doubt on their software and it's trustworthyness. In computer forensics it's ALL about being able to verify, without a shadow of doubt that something is what they say it is. Chain of custody rules everything. This blasts a huge gaping hole in all that. He's proven that chain of custody can be tampered with and undetected. Files can be planted, altered or erased. Reports can altered. Timestamps can…
Mostly. The other side gets all the evidence that the opposing side sees. They both get a chance to review it.
> Chain of custody rules everything.
Agree.
> This blasts a huge gaping hole in all that.
Not really. The analysis goes in two steps. One is to pull all the data from the phone, in a chain-of-custody manner. In an adversarial case, both sides can do this.
The collection and analysis go into two steps. First is moving the data to windows box. Next is the analysis. As I understand it, the analysis portion is where things can explode. Then, if in the hands of someone skilled in forensics, the extracted data would be saved in some other device, possibly to be shared with the other side. Then the risky, potentially explosive analysis would be done. It is very unlikely that all previous cases exist on that device and nowhere else.
Therefore,
> It calls all past and future cellbrite reports into question.
is not true, as the extracted files are likely not on the collecting windows device.
In any case, it is not clear how many uses of this device are in actual legal environments.
Re: Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer
#129A reminder that you can pair lock your iPhone to prevent analysis by Cellebrite or similar tools: https://arkadiyt.com/2019/10/07/pair-locking-your-iphone-wit...
All of these are based on the assumption that the attacker has physical access to the unlocked phone, right? I'm trying to understand the risk profile here. I guess I see the value for, e.g., a border crossing, where they can inconvenience you and ask you to unlock your phone, but instead of flicking through your messages briefly, they authorize a pairing and quickly backup your entire disk content. You expected a qu…
Well, mostly yes, that's considering Cellebrite doesn't have 0-days or other exploits which can send a SMS to the device or similar things. Using Cellebrite's software you can also send silent SMS, so it's not far off either.
A german Cellebrite ambassador showed me and colleagues the mentioned tools of the blog post and told us he participates at Law Enforcement raids. At 6 in the morning they raid the houses of the suspects, detain them and immediately ask for PINs and passwords. He said that surprisingly often it works and no further decryption tries have to be performed.
Re: Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer
#130> One way to think about Cellebrite’s products is that if someone is physically holding your unlocked device in their hands, they could open whatever apps they would like and take screenshots of everything in them to save and go over later. Cellebrite essentially automates that process for someone holding your device in their hands. Aren't Cellebrite products/services more advanced than that? I mean don't they use pu…
They are more advanced typically than just extracting data from a phone. Not sure to which extent they advertise it brazenly though. Fairly certain they blog about it a lot