Live data from Hacker News

Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer

signal.org

201–210 of 352 posts

Re: Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer

#201
post #31

Earlier quoted context omitted.

You wouldn't imply that Signal had framed you. You would imply that someone else had framed you using the same vulnerabilities as Signal has now indicated exists. i.e. You can't trust Cellebrite because it's now known to be trivial to subvert their software. It's also difficult for Cellebrite to prove that there aren't remaining vulnerabilities in their software since Signal didn't disclose the problems they found an…

It depends on the standard of reliability required. A good defence legal team might use this to argue that the phone data wouldn't be sufficient evidence in the actual criminal proceedings, you do need to prove things beyond all reasonable doubt there; however, even with all these caveats it would be sufficient to use that phone data for investigative purposes and as probable cause for getting a warrant for something…

That’s not true, at least if we’re talking fourth amendment issues in the US. If the evidence was thrown out, any additional information gleaned from that evidence could be thrown out too. And in a scenario like what you described, it likely would.

That’s not a guarantee, of course, and it could be possible for police to corroborate that you had contact with someone else in another way (through records from a wireless carrier or by doing shoe leather investigative work) and use try to get data on that person to get them to testify, but if their only link was through messages that had been deemed inadmissible, they can’t use that witness.

The more likely question in a scenario you describe would be if the compromised Signal data would be enough to raise questions about the validity of all the data on the device. I.e., if Signal is out, can they use information from WhatsApp or iMessage or whatever. Past case law would suggest that once compromised, all of the evidence from the device is compromised — but a judge might rule otherwise.

It would be cool if Signal or another app could use those exploits they’ve uncovered to inject randomized data into the data stores of other messaging applications too. You know. Just as an experiment.

Re: Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer

#202
post #135

Earlier quoted context omitted.

As in https://www.securityweek.com/forensics-tool-flaw-allows-hack... ., yet it is used in cases large and small, civil, criminal, federal state.

Matt Blaze did some research on this, and it seems to turn out that when you put an argument like this in front of a judge or jury, ultimately you have to back it up with evidence that it actually happened; it's not enough to say that the potential existed. Which makes sense, because the potential exists for a lot of stuff, including stuff we don't often talk about.

I think this post by signal is not much beyond exceedingly well-crafted nerd sniping [edited for claity]

Re: Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer

#203
post #80

Earlier quoted context omitted.

The digital equivalent of "stop hitting yourself". Notwithstanding their crypto issue, this gives me renewed confidence in Signal's team.

To me it seems more like the equivalent of leaving booby trapped packages to be found by porch pirates. Or putting laxatives (or worse) in your sandwich to get back at the unknown coworker stealing your lunch. Both of which are considered illegal in the US. Assuming these files actually contain exploits. Maybe they do maybe they don't. You feeling lucky Cellebrite?

The question of whether damaging reports would be illegal is separate from whether booby traps are illegal. And they're not, in the broad case: Booby trapped packages are only illegal if they cause bodily harm or damage or are negligent along those lines.

Re: Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer

#204

Cellebrite doesn't even have a bug bounty programme or contact to report their bugs. Last year I've managed to gain partial access to one of their systems and it took me weeks emailing their internal email addresses to finally fix the bug. They were total ass about it. Now I've got complete access to their entire database and I don't know what do. Can HN advise?

[deleted]

Re: Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer

#205

Earlier quoted context omitted.

Signal is going to start attacking third-party tools once it's installed on your phone. It's as though Theo decided that OpenSSH should respond to portscanners by trying to pwn the source systems.

And why shouldn’t OpenSSH do that?

Because I have zero interest in running attack software.

Re: Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer

#206

Wow, that video made my day. This bit is key: > "For example, by including a specially formatted but otherwise innocuous file in an app on a device that is then scanned by Cellebrite, it’s possible to execute code that modifies not just the Cellebrite report being created in that scan, but also all previous and future generated Cellebrite reports from all previously scanned devices and all future scanned devices in a…

The video made my inner child feel truly vindicated with my choice of username.

Re: Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer

#207
post #7

This is truly a hacker’s retort. It attacks Cellebrite's ability to operate by casting doubt on the reports generated by the product that their customers may wish to use in court. It places them in legal peril from Apple, and removes any cover Apple would have to not take legal action. (I assume someone at Apple knew they were shipping their DLLs?) It makes a thinly-veiled threat that any random Signal user's data ma…

Add one more: Anyone publicly attacking Signal's privacy in the future is painting a very large target on their forehead.

There's a difference between attacking their privacy (which is fair and should be done regularly if users' privacy is at stake) and claiming access to secure data that is wholly untrue.

Re: Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer

#208

Earlier quoted context omitted.

Doesn't matter. When you can go through every message on someones phone back for years, I'm sure you can find something to put nearly anyone in prison for. No need to tell the court how you found out about the lawnmowing for the neighbour that was never reported to the IRS...

When you can call into question the data integrity of the items on the device and whether the information from that device is accurate or was inserted by the machine used to break into it, that is some very basic fourth amendment stuff that could possibly get all items taken from the device deemed inadmissible.

Eh, this goes two ways. Cellebrite is rarely going to result in the only meaningful evidence that proves a single element of the offense. Instead, it is often used to further an investigation in order to find evidence that is more damning and of a higher evidentiary value. Fortunately for law enforcement, the integrity of the Cellebrite-obtained data is all that important if it leads to further evidence that is more significant.

Re: Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer

#209
>Since almost all of Cellebrite’s code exists to parse untrusted input that could be formatted in an unexpected way to exploit memory corruption or other vulnerabilities in the parsing software, one might expect Cellebrite to have been extremely cautious.

>Looking at both UFED and Physical Analyzer, though, we were surprised to find that very little care seems to have been given to Cellebrite’s own software security.

People keep saying this. It has never changed since the 90s. There is no bar to become a "software engineer".

Re: Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer

#210
post #67

Earlier quoted context omitted.

> It attacks Cellebrite's ability to operate by casting doubt on the reports generated by the product that their customers may wish to use in court. Fortunately, parallel construction means you never really have to throw out bad evidence as long as you can find some good evidence too!

Knowing that at least one row of data in a database might have been modified randomly means you can't fully trust any one line in the database completely. It reminds me of the story of https://en.wikipedia.org/wiki/Annie_Dookhan

Sure, but the data on the phone will lead you to evidence in the real world, which will be meaningful proof that can be used in court.
Post reply on HN