Live data from Hacker News

Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer

signal.org

231–240 of 352 posts

Re: Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer

#231

Cellebrite doesn't even have a bug bounty programme or contact to report their bugs. Last year I've managed to gain partial access to one of their systems and it took me weeks emailing their internal email addresses to finally fix the bug. They were total ass about it. Now I've got complete access to their entire database and I don't know what do. Can HN advise?

This definitely isn't a trap.

Re: Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer

#232

Truly a jaw dropping blog post, as the top comment currently states, Apple may be legally required to at the very least, comment on this situation.

Don't confuse the thing where a company has to defend its trademarks to keep them with copyrights (which do not require active defense to maintain).

This, if Apple does pursue it, is a copyright matter, not trademark.

Re: Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer

#233
post #229

To be fair, this vulnerability disclosure is worthless, because it wasn’t actually disclosed—the true vulnerability is purported to be in the file that Signal uses to execute arbitrary code, of which the details are not shared. We are relying on pure trust that the video demonstration of the purported vulnerability is not a forgery. Additionally, I see from the video that the purported vulnerability is present in UFE…

Many vulnerabilities are disclosed without simultaneous disclosure of the PoC. That doesn't make it worthless. Also, not disclosing specifics is reasonable here, given that the vendor is themselves known for using, hoarding, and selling access to 0days. There is no obligation for a researcher to share their research with such a corrupt vendor.

I agree that the vendor is detestable, but we must decouple that sentiment from the idea that this blog post compromises Cellebrite’s product or credibility in any way.

As it stands, the vulnerability is not reproducible by anyone other than Signal. Reproducibility is key in the scientific method and in the court of law.

Re: Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer

#234
post #112
post #6

So I wonder, why disclose this? This will just prompt Cellebrite to improve its security process and sandbox the entire tool. If they wanted to destroy the credibility of the tool, using the vulnerabilities to silently tamper with the collected data or even leaking it online would be a much better option and hit them without any warning, not only jeopardizing those cases but forever casting doubt on not just Cellebri…

Probably disclosure is the best option. Silently tamper with the data might cross a legal line. doing this might put at risk current or past cases where there is a legitimate reason to use this sort of tool. Privacy can be hard. While i 100% defend everybody has the right to privacy, i can also see the need for the capability to break it. Maybe the answer for this is a very tight regulation around the uses of this ki…

> Privacy can be hard. While i 100% defend everybody has the right to privacy, i can also see the need for the capability to break it. Maybe the answer for this is a very tight regulation around the uses of this kind of hardware/software, but that regulation would have to keep up with the pace of technology

i've always wondered if there could be a cryptographic solution to this. issuing decryption keys to governments seems rife for abuse, but some sort of multi-party situation where governmental and non-governmental entities have to cooperate (with actual multiparty key material) to perform a decryption authorized by warrants- with said non-governmental agencies acting as a check on usage of those warrants, their frequency and the eventual publication of their usage could be an interesting approach.

personally i think strong encryption should be a requirement for digital evidence, but even that can be forged.

strange times we live in.

Re: Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer

#235
Cellebrite's initial response[1] includes this gem

"We have strict licensing policies that govern how customers are permitted to use our technology and do not sell to countries under sanction by the US, Israel or the broader international community."

And these policies are obviously quite effective at preventing such uses.

[1] https://www.theregister.com/2021/04/21/signal_cellebrite/

Re: Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer

#236

This is something I have personally looked at as an owner of a UFED touch device (1st gen). By default your software runs in a non-priviledged account but who's to say one of files isn't just straight up being read by FFMPEG and adding or removing evidence from the final report. The official Cellebrite policy has always been "don't worry, if you get stuck, we can send you an expert to testify to the reliability of th…

> As just one example (unrelated to what follows), their software bundles FFmpeg DLLs that were built in 2012 and have not been updated since then.

This purported vulnerability does not rely on FFmpeg, hence the disclaimer.

Re: Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer

#237

> By a truly unbelievable coincidence, I was recently out for a walk when I saw a small package fall off a truck ahead of me. As I got closer, the dull enterprise typeface slowly came into focus: Cellebrite. Inside, we found the latest versions of the Cellebrite software, a hardware dongle designed to prevent piracy (tells you something about their customers I guess!), and a bizarrely large number of cable adapters.…

plausible deniability

Re: Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer

#238

Wow, that video made my day. This bit is key: > "For example, by including a specially formatted but otherwise innocuous file in an app on a device that is then scanned by Cellebrite, it’s possible to execute code that modifies not just the Cellebrite report being created in that scan, but also all previous and future generated Cellebrite reports from all previously scanned devices and all future scanned devices in a…

The video made my inner child feel truly vindicated with my choice of username.

Same here.

Re: Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer

#240

Earlier quoted context omitted.

Eh, this goes two ways. Cellebrite is rarely going to result in the only meaningful evidence that proves a single element of the offense. Instead, it is often used to further an investigation in order to find evidence that is more damning and of a higher evidentiary value. Fortunately for law enforcement, the integrity of the Cellebrite-obtained data is all that important if it leads to further evidence that is more…

I don’t think that’s true. There’s a legal idea of “fruit of the poisonous tree”[0] that basically says you can’t use bad evidence, either in court or as an excuse to collect more, valid evidence. The defense attorney would say “if it hadn’t been for that completely untrustworthy Cellebrite evidence, the police wouldn’t have been able to get that search warrant they used to find the gun at his house, so we want that…

> I don’t think that’s true. There’s a legal idea of “fruit of the poisonous tree”[0] that basically says you can’t use bad evidence, either in court or as an excuse to collect more, valid evidence.

I think the police have been using "parallel construction" to get around that for some time.

https://en.wikipedia.org/wiki/Parallel_construction

> Parallel construction is a law enforcement process of building a parallel, or separate, evidentiary basis for a criminal investigation in order to conceal how an investigation actually began.[1]

> In the US, a particular form is evidence laundering, where one police officer obtains evidence via means that are in violation of the Fourth Amendment's protection against unreasonable searches and seizures, and then passes it on to another officer, who builds on it and gets it accepted by the court under the good-faith exception as applied to the second officer.[2] This practice gained support after the Supreme Court's 2009 Herring v. United States decision.

Post reply on HN