Live data from Hacker News

Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer

signal.org

121–130 of 352 posts

Re: Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer

#121
post #6

So I wonder, why disclose this? This will just prompt Cellebrite to improve its security process and sandbox the entire tool. If they wanted to destroy the credibility of the tool, using the vulnerabilities to silently tamper with the collected data or even leaking it online would be a much better option and hit them without any warning, not only jeopardizing those cases but forever casting doubt on not just Cellebri…

The public disclosure about the Apple DLLs could potentially be used to drag Apple into any legal case between somebody versus Cellebrite. The disclosure needs to be public versus private or under seal or whatever to absolve the Cellebrite counterparty of any liability from reverse engineering. Suddenly Apple is now in potential collusion with Cellebrite. Or maybe not. This public disclosure makes the threat of Disco…

does cellebrite appear in any legit court cases? from this blog post it sounds like only "authoritarian" regimes use it. i doubt it would appear in any legit case. it's a shady tool. they'll use it to gather info but will not present this info directly in court, instead use it to gather legitimate proof, if needed.

Re: Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer

#122

Earlier quoted context omitted.

"falling off a truck" is slang for "was stolen".

TIL: https://idioms.thefreedictionary.com/fall+off+a+truck Edit: looking up a bit more, it seems like this idiom is used to denote goods sold for cheap because they were stolen. Like "Bob is selling genuine iPhones very cheap, I fear they fell from the back of a truck". Edit edit: I initially took it as "we won't tell how we got this", because I didn't know this idiom, but it seems several people agree with this inte…

That isn't quite right. Although it's commonly used to describe something that's been stolen, it's more generally used to indicate that the speaker doesn't want to talk about where it came from. That's how it's been used in this article.

Re: Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer

#123
post #86

Earlier quoted context omitted.

This still works as written. Just test it yourself with a Mac and Apple Configurator.

I mean, “the iPhone prevents well-behaved software from accessing data without a password” and “software, known to exploit vulnerabilities to get around security features, currently doesn’t have any such exploits” are very different.

Every stone we can put in the way of surveillance helps.

Re: Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer

#124

> In completely unrelated news, upcoming versions of Signal will be periodically fetching files to place in app storage. These files are never used for anything inside Signal and never interact with Signal software or data, but they look nice, and aesthetics are important in software. I wish I could see those files in action...

I don't get it, can anyone elaborate on what they are talking about there?

Re: Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer

#125

Earlier quoted context omitted.

Indeed, how convenient . If it truly did fall off the truck right while he is on a walk then there is the possibility that is a rubber duckie attack. This is basically the equivalent of leaving a USB flash drive lying around. I hope the author took the necessary precautions when reverse engineering the device. Companies like cellebrite have deep connections to certain three letter communities that staging this sort o…

I think we can be relatively confident that the connected machine was airgapped and perhaps run in a VM. Perhaps even in a faraday cage..

> (...) and perhaps run in a VM.

One of the screenshots[0] shows the VMware Tools Service running, so yeah, looks like a virtualized guest.

[0]: https://signal.org/blog/images/cellebrite-dlls-loaded.png

Re: Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer

#126
>By a truly unbelievable coincidence, I was recently out for a walk when I saw a small package fall off a truck ahead of me. As I got closer, the dull enterprise typeface slowly came into focus: Cellebrite.

That's just hilarious! Nice way of saying we got our hands onto one of these boxes, but we don't want to reveal how. It fell of a truck.

Re: Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer

#127

> In completely unrelated news, upcoming versions of Signal will be periodically fetching files to place in app storage. These files are never used for anything inside Signal and never interact with Signal software or data, but they look nice, and aesthetics are important in software. I wish I could see those files in action...

I don't get it, can anyone elaborate on what they are talking about there?

They are implying that future versions of Signal will drop random files on your phone that "may or may not" cause damage to Cellebrite systems.

They are basically putting the threat out that if you use Cellebrite on Signal in the future, you might not get the data you expect, and at worst, it may corrupt the report/evidence.

This also brings into question the chain of custody, as an untrusted device being imaged can alter reports of unrelated devices.

Re: Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer

#128
post #89

Earlier quoted context omitted.

You can't just claim an unknown entity framed you and hope to get anywhere. Heck, you could just as well claim that Cellebrite themselves had it in for you. Cellebrite has never claimed any particular exploits in Signal. Signal is exploitable in this particular way for entirely obvious and common reasons.

It's about casting doubt on their software and it's trustworthyness. In computer forensics it's ALL about being able to verify, without a shadow of doubt that something is what they say it is. Chain of custody rules everything. This blasts a huge gaping hole in all that. He's proven that chain of custody can be tampered with and undetected. Files can be planted, altered or erased. Reports can altered. Timestamps can…

> In computer forensics it's ALL about being able to verify, without a shadow of doubt that something is what they say it is

Mostly. The other side gets all the evidence that the opposing side sees. They both get a chance to review it.

> Chain of custody rules everything.

Agree.

> This blasts a huge gaping hole in all that.

Not really. The analysis goes in two steps. One is to pull all the data from the phone, in a chain-of-custody manner. In an adversarial case, both sides can do this.

The collection and analysis go into two steps. First is moving the data to windows box. Next is the analysis. As I understand it, the analysis portion is where things can explode. Then, if in the hands of someone skilled in forensics, the extracted data would be saved in some other device, possibly to be shared with the other side. Then the risky, potentially explosive analysis would be done. It is very unlikely that all previous cases exist on that device and nowhere else.

Therefore,

> It calls all past and future cellbrite reports into question.

is not true, as the extracted files are likely not on the collecting windows device.

In any case, it is not clear how many uses of this device are in actual legal environments.

Re: Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer

#129
post #64

A reminder that you can pair lock your iPhone to prevent analysis by Cellebrite or similar tools: https://arkadiyt.com/2019/10/07/pair-locking-your-iphone-wit...

All of these are based on the assumption that the attacker has physical access to the unlocked phone, right? I'm trying to understand the risk profile here. I guess I see the value for, e.g., a border crossing, where they can inconvenience you and ask you to unlock your phone, but instead of flicking through your messages briefly, they authorize a pairing and quickly backup your entire disk content. You expected a qu…

> unlocked phone

Well, mostly yes, that's considering Cellebrite doesn't have 0-days or other exploits which can send a SMS to the device or similar things. Using Cellebrite's software you can also send silent SMS, so it's not far off either.

A german Cellebrite ambassador showed me and colleagues the mentioned tools of the blog post and told us he participates at Law Enforcement raids. At 6 in the morning they raid the houses of the suspects, detain them and immediately ask for PINs and passwords. He said that surprisingly often it works and no further decryption tries have to be performed.

Re: Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer

#130

> One way to think about Cellebrite’s products is that if someone is physically holding your unlocked device in their hands, they could open whatever apps they would like and take screenshots of everything in them to save and go over later. Cellebrite essentially automates that process for someone holding your device in their hands. Aren't Cellebrite products/services more advanced than that? I mean don't they use pu…

They are more advanced typically than just extracting data from a phone. Not sure to which extent they advertise it brazenly though. Fairly certain they blog about it a lot

the cellebrite ambassador we talked to (as private company) basically bragged they were the ones that unlocked the San Bernadirno iPhone. I'm sure towards government officials and Law Enforcement they brag even more.
Post reply on HN