Cellebrite doesn't even have a bug bounty programme or contact to report their bugs. Last year I've managed to gain partial access to one of their systems and it took me weeks emailing their internal email addresses to finally fix the bug. They were total ass about it. Now I've got complete access to their entire database and I don't know what do. Can HN advise?
Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer
181–190 of 352 posts
Re: Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer
#182Earlier quoted context omitted.
They are implying that future versions of Signal will drop random files on your phone that "may or may not" cause damage to Cellebrite systems. They are basically putting the threat out that if you use Cellebrite on Signal in the future, you might not get the data you expect, and at worst, it may corrupt the report/evidence. This also brings into question the chain of custody, as an untrusted device being imaged can…
Damn, a chain of custody where the thing in evidence is also part of not only its own chain but also those of other evidence acquired afterwards? I can't imagine what kind of case law exists around that, but I'm sure it's hilarious!
And prior extracts on the device.
Re: Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer
#183Cellebrite doesn't even have a bug bounty programme or contact to report their bugs. Last year I've managed to gain partial access to one of their systems and it took me weeks emailing their internal email addresses to finally fix the bug. They were total ass about it. Now I've got complete access to their entire database and I don't know what do. Can HN advise?
Re: Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer
#184This is truly a hacker’s retort. It attacks Cellebrite's ability to operate by casting doubt on the reports generated by the product that their customers may wish to use in court. It places them in legal peril from Apple, and removes any cover Apple would have to not take legal action. (I assume someone at Apple knew they were shipping their DLLs?) It makes a thinly-veiled threat that any random Signal user's data ma…
Sadly I suspect the people in law enforcement who make purchasing decisions never read the Signal blog, and therefore all these points will be moot.
Re: Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer
#185Earlier quoted context omitted.
Damn, a chain of custody where the thing in evidence is also part of not only its own chain but also those of other evidence acquired afterwards? I can't imagine what kind of case law exists around that, but I'm sure it's hilarious!
> also those of other evidence acquired afterwards And prior extracts on the device.
Re: Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer
#186Earlier quoted context omitted.
Files will only be returned for accounts that have been active installs for some time already, and only probabilistically in low percentages based on phone number sharding. We have a few different versions of files that we think are aesthetically pleasing, and will iterate through those slowly over time. Pretty sure it's the former, since the above is a way to ensure that Cellebrite can't just gather all implied expl…
This indeed looks like a FUD statement, implying that they can have an infinite amount of potential vulnerabilities. Realistically though, writing parsers that do not yield control of your whole device is not that complex. The people exploiting iOS zero days can certainly do it.
Re: Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer
#187Earlier quoted context omitted.
IANAL but AFAIK you can be held in contempt of court if you don't provide it when asked if they're already convinced it's yours and has incriminating evidence on it. Article below, although it looks like fairly recent (not super established) jurisprudence. [1] https://goldsteinmehta.com/blog/can-the-police-force-you-to-...
At issue there is the "foregone conclusion" exception to the 5th amendment. As far as I understand things you've lost the case by that point anyway. Even then, I believe there would still be the additional issue of demonstrating that the defendant actually knows the password. Which is why I previously mentioned that if you openly admit to knowing the password then you likely have a problem. (This came up in a case wh…
The unclear part seems to be how strong the evidence needs to be that the device is yours and that the evidence is on there. In this case, his sister testified to both. But would it be strong enough with forensic evidence alone? Unclear.
> As far as I understand things you've lost the case by that point anyway.
Perhaps, but there may still be significance to what's on that drive. There may be incriminating evidence there for other crimes for which you're not yet being prosecuted.
> Even then, I believe there would still be the additional issue of demonstrating that the defendant actually knows the password.
They're saying the sister's testimony was sufficient to prove that he knew the passwords previously.
Proving present-day capability to decrypt doesn't seem to be necessary, at least in the article I linked.
> The federal court denied the Motion to Quash and directed Doe to unlock the devices for the investigators. Doe did not appeal, but he refused to unlock some of the devices, claiming that he had forgotten the passwords. He was eventually held in contempt by the District Court, and the Court ordered that he remain in federal custody until he was willing to unlock the devices.
The accused claimed he could not decrypt the hard drive because he had forgotten the passwords, but he was still being held in contempt.
Re: Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer
#188I don't understand the seeming incongruity between these two statements: On the one hand: > One way to think about Cellebrite’s products is that if someone is physically holding your unlocked device in their hands, they could open whatever apps they would like and take screenshots of everything in them to save and go over later. Cellebrite essentially automates that process for someone holding your device in their ha…
Yes, they even brag about it in their marketing materials: https://www.cellebrite.com/en/a-practical-guide-to-checkm8/
That's a public vunerability, it's anyone's guess how many nonpublic ones they're using.
Re: Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer
#189Earlier quoted context omitted.
Files will only be returned for accounts that have been active installs for some time already, and only probabilistically in low percentages based on phone number sharding. We have a few different versions of files that we think are aesthetically pleasing, and will iterate through those slowly over time. Pretty sure it's the former, since the above is a way to ensure that Cellebrite can't just gather all implied expl…
This indeed looks like a FUD statement, implying that they can have an infinite amount of potential vulnerabilities. Realistically though, writing parsers that do not yield control of your whole device is not that complex. The people exploiting iOS zero days can certainly do it.
Re: Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer
#190Earlier quoted context omitted.
I don't get it, can anyone elaborate on what they are talking about there?
Signal is going to start attacking third-party tools once it's installed on your phone. It's as though Theo decided that OpenSSH should respond to portscanners by trying to pwn the source systems.