Live data from Hacker News

Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer

signal.org

171–180 of 352 posts

Re: Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer

#172

Truly a jaw dropping blog post, as the top comment currently states, Apple may be legally required to at the very least, comment on this situation.

> Apple may be legally required to at the very least, comment on this situation. "Required" to comment? By whom and for what reason?

Sending a cease and desist to Cellebrite for shipping their DLLs in their product I imagine.

Obviously there may be some backchannel, but that is probably how it would go if you assume Apple and Cellebrite have no relationship.

Re: Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer

#173

Earlier quoted context omitted.

They won't be moot when defense lawyers bring them up.

Doesn't matter. When you can go through every message on someones phone back for years, I'm sure you can find something to put nearly anyone in prison for. No need to tell the court how you found out about the lawnmowing for the neighbour that was never reported to the IRS...

When you can call into question the data integrity of the items on the device and whether the information from that device is accurate or was inserted by the machine used to break into it, that is some very basic fourth amendment stuff that could possibly get all items taken from the device deemed inadmissible.

Re: Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer

#174

> In completely unrelated news, upcoming versions of Signal will be periodically fetching files to place in app storage. These files are never used for anything inside Signal and never interact with Signal software or data, but they look nice, and aesthetics are important in software. I wish I could see those files in action...

signal wants to pick a fight with a grey company that gets money for cracking apps? not a good idea

They're already picking a fight with Cellebrite simply by existing, as Signal is antithetical to everything that Cellebrite stands for.

Re: Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer

#175
post #31

Earlier quoted context omitted.

I really seriously doubt that anyone would ever advance the idea that Signal had deliberately framed them by creating false data on their phone. I don't see this as much more than pointing out that Cellebrite has vulnerabilities, just like the ones they exploit.

You wouldn't imply that Signal had framed you. You would imply that someone else had framed you using the same vulnerabilities as Signal has now indicated exists. i.e. You can't trust Cellebrite because it's now known to be trivial to subvert their software. It's also difficult for Cellebrite to prove that there aren't remaining vulnerabilities in their software since Signal didn't disclose the problems they found an…

It depends on the standard of reliability required. A good defence legal team might use this to argue that the phone data wouldn't be sufficient evidence in the actual criminal proceedings, you do need to prove things beyond all reasonable doubt there; however, even with all these caveats it would be sufficient to use that phone data for investigative purposes and as probable cause for getting a warrant for something else, and then use that for the actual conviction.

For example, let's say they extract the Signal message data from your phone. You successfully convince everyone that this data might have been the result of some tampering. However, that doesn't prevent investigators from using that message history to find the other person, and get them to testify against you.

Re: Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer

#176
post #7

This is truly a hacker’s retort. It attacks Cellebrite's ability to operate by casting doubt on the reports generated by the product that their customers may wish to use in court. It places them in legal peril from Apple, and removes any cover Apple would have to not take legal action. (I assume someone at Apple knew they were shipping their DLLs?) It makes a thinly-veiled threat that any random Signal user's data ma…

IANAL, and I don't speak for Apple, but as far as I can tell, the part about Apple is nonsense. CoreFoundation is open source: https://github.com/opensource-apple/CF libdispatch is open source: https://apple.github.io/swift-corelibs-libdispatch/post/libd... ASL is open source: https://opensource.apple.com/source/syslog/syslog-349.1.1/li... The objective C runtime is open source: https://github.com/opensource-apple/ob…

Yes, but the copy shipped is signed by Apple. i.e. they did not compile their own copy.

Re: Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer

#177

Earlier quoted context omitted.

Signal is going to start attacking third-party tools once it's installed on your phone. It's as though Theo decided that OpenSSH should respond to portscanners by trying to pwn the source systems.

No, because that would be active retaliation. More realistically it is like dropping a file on your private file server DONT_RUN_THIS_BLOWS_UP_YOUR_COMPUTER.exe. You never run it, but maybe somebody exploits your file server, gets all your files, and automatically runs them? Oh well.

It really is like dropping a file on your private file server DONT_RUN_THIS_BLOWS_UP_YOUR_COMPUTER.exe - but contrary to your expectations, it's not "oh well", if you placed it there with the intent to trap someone who you expect to be looking at your computer, you may well be liable if their computer blows up, there's no significant difference from active retaliation - the consequences are there, the intent is there, the act is there, it's pretty much the same.

Of course, if some criminal exploits your file server, they are not likely to press charges, but if it triggers on law enforcement who have a warrant to scan your fileserver, that's a different issue.

You'd be just as liable as for physical boobytraps on your property, with pretty much the same reasoning.

Re: Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer

#178
post #7

This is truly a hacker’s retort. It attacks Cellebrite's ability to operate by casting doubt on the reports generated by the product that their customers may wish to use in court. It places them in legal peril from Apple, and removes any cover Apple would have to not take legal action. (I assume someone at Apple knew they were shipping their DLLs?) It makes a thinly-veiled threat that any random Signal user's data ma…

IANAL, and I don't speak for Apple, but as far as I can tell, the part about Apple is nonsense. CoreFoundation is open source: https://github.com/opensource-apple/CF libdispatch is open source: https://apple.github.io/swift-corelibs-libdispatch/post/libd... ASL is open source: https://opensource.apple.com/source/syslog/syslog-349.1.1/li... The objective C runtime is open source: https://github.com/opensource-apple/ob…

MobileDevice.framework isn't open source.

Re: Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer

#179
Cellebrite doesn't even have a bug bounty programme or contact to report their bugs.

Last year I've managed to gain partial access to one of their systems and it took me weeks emailing their internal email addresses to finally fix the bug. They were total ass about it.

Now I've got complete access to their entire database and I don't know what do. Can HN advise?

Re: Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer

#180

Earlier quoted context omitted.

> if I were compelled via court order to give my passcode In the US that won't work if unlocking the device requires a password or pin. In practice, you can't be compelled to provide that unless you openly admit that you know it. (Even then, the 5th amendment might afford you some protection.) YMMV, IANAL, etc.

IANAL but AFAIK you can be held in contempt of court if you don't provide it when asked if they're already convinced it's yours and has incriminating evidence on it. Article below, although it looks like fairly recent (not super established) jurisprudence. [1] https://goldsteinmehta.com/blog/can-the-police-force-you-to-...

At issue there is the "foregone conclusion" exception to the 5th amendment. As far as I understand things you've lost the case by that point anyway.

Even then, I believe there would still be the additional issue of demonstrating that the defendant actually knows the password. Which is why I previously mentioned that if you openly admit to knowing the password then you likely have a problem. (This came up in a case where the defendant admitted to the FBI that he was capable of decrypting an external hard drive but refused to do so because "we both know what's on there".)

Post reply on HN