This rocks so hard. Also the Prodigy soundtrack! Takes me back.
Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer
171–180 of 352 posts
Re: Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer
#172Truly a jaw dropping blog post, as the top comment currently states, Apple may be legally required to at the very least, comment on this situation.
> Apple may be legally required to at the very least, comment on this situation. "Required" to comment? By whom and for what reason?
Obviously there may be some backchannel, but that is probably how it would go if you assume Apple and Cellebrite have no relationship.
Re: Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer
#173Earlier quoted context omitted.
They won't be moot when defense lawyers bring them up.
Doesn't matter. When you can go through every message on someones phone back for years, I'm sure you can find something to put nearly anyone in prison for. No need to tell the court how you found out about the lawnmowing for the neighbour that was never reported to the IRS...
Re: Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer
#174> In completely unrelated news, upcoming versions of Signal will be periodically fetching files to place in app storage. These files are never used for anything inside Signal and never interact with Signal software or data, but they look nice, and aesthetics are important in software. I wish I could see those files in action...
signal wants to pick a fight with a grey company that gets money for cracking apps? not a good idea
Re: Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer
#175Earlier quoted context omitted.
I really seriously doubt that anyone would ever advance the idea that Signal had deliberately framed them by creating false data on their phone. I don't see this as much more than pointing out that Cellebrite has vulnerabilities, just like the ones they exploit.
You wouldn't imply that Signal had framed you. You would imply that someone else had framed you using the same vulnerabilities as Signal has now indicated exists. i.e. You can't trust Cellebrite because it's now known to be trivial to subvert their software. It's also difficult for Cellebrite to prove that there aren't remaining vulnerabilities in their software since Signal didn't disclose the problems they found an…
For example, let's say they extract the Signal message data from your phone. You successfully convince everyone that this data might have been the result of some tampering. However, that doesn't prevent investigators from using that message history to find the other person, and get them to testify against you.
Re: Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer
#176This is truly a hacker’s retort. It attacks Cellebrite's ability to operate by casting doubt on the reports generated by the product that their customers may wish to use in court. It places them in legal peril from Apple, and removes any cover Apple would have to not take legal action. (I assume someone at Apple knew they were shipping their DLLs?) It makes a thinly-veiled threat that any random Signal user's data ma…
IANAL, and I don't speak for Apple, but as far as I can tell, the part about Apple is nonsense. CoreFoundation is open source: https://github.com/opensource-apple/CF libdispatch is open source: https://apple.github.io/swift-corelibs-libdispatch/post/libd... ASL is open source: https://opensource.apple.com/source/syslog/syslog-349.1.1/li... The objective C runtime is open source: https://github.com/opensource-apple/ob…
Re: Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer
#177Earlier quoted context omitted.
Signal is going to start attacking third-party tools once it's installed on your phone. It's as though Theo decided that OpenSSH should respond to portscanners by trying to pwn the source systems.
No, because that would be active retaliation. More realistically it is like dropping a file on your private file server DONT_RUN_THIS_BLOWS_UP_YOUR_COMPUTER.exe. You never run it, but maybe somebody exploits your file server, gets all your files, and automatically runs them? Oh well.
Of course, if some criminal exploits your file server, they are not likely to press charges, but if it triggers on law enforcement who have a warrant to scan your fileserver, that's a different issue.
You'd be just as liable as for physical boobytraps on your property, with pretty much the same reasoning.
Re: Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer
#178This is truly a hacker’s retort. It attacks Cellebrite's ability to operate by casting doubt on the reports generated by the product that their customers may wish to use in court. It places them in legal peril from Apple, and removes any cover Apple would have to not take legal action. (I assume someone at Apple knew they were shipping their DLLs?) It makes a thinly-veiled threat that any random Signal user's data ma…
IANAL, and I don't speak for Apple, but as far as I can tell, the part about Apple is nonsense. CoreFoundation is open source: https://github.com/opensource-apple/CF libdispatch is open source: https://apple.github.io/swift-corelibs-libdispatch/post/libd... ASL is open source: https://opensource.apple.com/source/syslog/syslog-349.1.1/li... The objective C runtime is open source: https://github.com/opensource-apple/ob…
Re: Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer
#179Last year I've managed to gain partial access to one of their systems and it took me weeks emailing their internal email addresses to finally fix the bug. They were total ass about it.
Now I've got complete access to their entire database and I don't know what do. Can HN advise?
Re: Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer
#180Earlier quoted context omitted.
> if I were compelled via court order to give my passcode In the US that won't work if unlocking the device requires a password or pin. In practice, you can't be compelled to provide that unless you openly admit that you know it. (Even then, the 5th amendment might afford you some protection.) YMMV, IANAL, etc.
IANAL but AFAIK you can be held in contempt of court if you don't provide it when asked if they're already convinced it's yours and has incriminating evidence on it. Article below, although it looks like fairly recent (not super established) jurisprudence. [1] https://goldsteinmehta.com/blog/can-the-police-force-you-to-...
Even then, I believe there would still be the additional issue of demonstrating that the defendant actually knows the password. Which is why I previously mentioned that if you openly admit to knowing the password then you likely have a problem. (This came up in a case where the defendant admitted to the FBI that he was capable of decrypting an external hard drive but refused to do so because "we both know what's on there".)