This is truly a hacker’s retort. It attacks Cellebrite's ability to operate by casting doubt on the reports generated by the product that their customers may wish to use in court. It places them in legal peril from Apple, and removes any cover Apple would have to not take legal action. (I assume someone at Apple knew they were shipping their DLLs?) It makes a thinly-veiled threat that any random Signal user's data ma…
Sadly I suspect the people in law enforcement who make purchasing decisions never read the Signal blog, and therefore all these points will be moot.
Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer
241–250 of 352 posts
Re: Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer
#242Earlier quoted context omitted.
Eh, this goes two ways. Cellebrite is rarely going to result in the only meaningful evidence that proves a single element of the offense. Instead, it is often used to further an investigation in order to find evidence that is more damning and of a higher evidentiary value. Fortunately for law enforcement, the integrity of the Cellebrite-obtained data is all that important if it leads to further evidence that is more…
I don’t think that’s true. There’s a legal idea of “fruit of the poisonous tree”[0] that basically says you can’t use bad evidence, either in court or as an excuse to collect more, valid evidence. The defense attorney would say “if it hadn’t been for that completely untrustworthy Cellebrite evidence, the police wouldn’t have been able to get that search warrant they used to find the gun at his house, so we want that…
Re: Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer
#243Earlier quoted context omitted.
They are not putting malware into their app. They are adding athletically pleasing files to their app. Is it Signals fault if someone else's software doesn't work properly with them? How can Signal test every piece of software to make sure it's compatible with their own software? Especially when the other software is using Signal in a unintended way. It's not signals job to secure 3rd party software, that's entirely…
Intent matters, come on, your arguments are ridiculuous. If one of the aesthetically pleasing files turns out to contain an exploit targeted at Cellebrite software, then it wouldn't be hard to convince a jury that this isn't a coincidence but intentional malware, especially combined with this wink-wink bragpost. It's not Signal's job to secure third party software, they can intentionally post incompatible data, but i…
Re: Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer
#244Earlier quoted context omitted.
All that trouble becaused a bag conveniently "fell from a truck". All in all I'm really happy for all this.
I found that funny too. It sounds to me like a good way to end up with the device to analyze without being constrained by a contract or EULA prohibiting it.
https://www.phrases.org.uk/meanings/fell-off-the-back-of-a-t...
Re: Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer
#245Earlier quoted context omitted.
Probably disclosure is the best option. Silently tamper with the data might cross a legal line. doing this might put at risk current or past cases where there is a legitimate reason to use this sort of tool. Privacy can be hard. While i 100% defend everybody has the right to privacy, i can also see the need for the capability to break it. Maybe the answer for this is a very tight regulation around the uses of this ki…
> Privacy can be hard. While i 100% defend everybody has the right to privacy, i can also see the need for the capability to break it. Maybe the answer for this is a very tight regulation around the uses of this kind of hardware/software, but that regulation would have to keep up with the pace of technology i've always wondered if there could be a cryptographic solution to this. issuing decryption keys to governments…
I would be willing to consider a solution where you need to have agreement from the UN Security council (maybe just the permanent members) in order to decrypt whatever you want. If you can get those countries to agree, it's probably important.
Re: Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer
#246Earlier quoted context omitted.
The public disclosure about the Apple DLLs could potentially be used to drag Apple into any legal case between somebody versus Cellebrite. The disclosure needs to be public versus private or under seal or whatever to absolve the Cellebrite counterparty of any liability from reverse engineering. Suddenly Apple is now in potential collusion with Cellebrite. Or maybe not. This public disclosure makes the threat of Disco…
does cellebrite appear in any legit court cases? from this blog post it sounds like only "authoritarian" regimes use it. i doubt it would appear in any legit case. it's a shady tool. they'll use it to gather info but will not present this info directly in court, instead use it to gather legitimate proof, if needed.
Re: Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer
#247Wow, that video made my day. This bit is key: > "For example, by including a specially formatted but otherwise innocuous file in an app on a device that is then scanned by Cellebrite, it’s possible to execute code that modifies not just the Cellebrite report being created in that scan, but also all previous and future generated Cellebrite reports from all previously scanned devices and all future scanned devices in a…
The video made my inner child feel truly vindicated with my choice of username.
Re: Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer
#248I don't understand the seeming incongruity between these two statements: On the one hand: > One way to think about Cellebrite’s products is that if someone is physically holding your unlocked device in their hands, they could open whatever apps they would like and take screenshots of everything in them to save and go over later. Cellebrite essentially automates that process for someone holding your device in their ha…
I think what he meant to say was that if Cellebrite is used on your locked phone it could be the equivalent of a person having your unlocked phone in their hands where they can do whatever they want. Only cellbrite doesn't do look at random things, it grabs everything.
Cellebrite devices are also frequently used by phone carriers to image your old phone and transfer the data to your newly purchased phone, to give you a clearer idea of what they can do.
Re: Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer
#249Earlier quoted context omitted.
The public disclosure about the Apple DLLs could potentially be used to drag Apple into any legal case between somebody versus Cellebrite. The disclosure needs to be public versus private or under seal or whatever to absolve the Cellebrite counterparty of any liability from reverse engineering. Suddenly Apple is now in potential collusion with Cellebrite. Or maybe not. This public disclosure makes the threat of Disco…
does cellebrite appear in any legit court cases? from this blog post it sounds like only "authoritarian" regimes use it. i doubt it would appear in any legit case. it's a shady tool. they'll use it to gather info but will not present this info directly in court, instead use it to gather legitimate proof, if needed.
Re: Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer
#250Earlier quoted context omitted.
At issue there is the "foregone conclusion" exception to the 5th amendment. As far as I understand things you've lost the case by that point anyway. Even then, I believe there would still be the additional issue of demonstrating that the defendant actually knows the password. Which is why I previously mentioned that if you openly admit to knowing the password then you likely have a problem. (This came up in a case wh…
> At issue there is the "foregone conclusion" exception to the 5th amendment. The unclear part seems to be how strong the evidence needs to be that the device is yours and that the evidence is on there. In this case, his sister testified to both. But would it be strong enough with forensic evidence alone? Unclear. > As far as I understand things you've lost the case by that point anyway. Perhaps, but there may still…
The 5th amendment protects you from having to testify against yourself, but it doesn't protect you from having to turn over incriminating evidence against yourself. The 4th amendment protects your stuff, but only up to the point of requiring probable cause for a warrant.
At issue in these sorts of encrypted storage scenarios is whether you would be incriminating yourself by demonstrating that you know the password. Knowing the password for an encrypted device basically proves that it's your device, so forcing you to decrypt a device would amount to forcing you to testify against yourself in the event that there is doubt about whether the device is yours.
So to force you to decrypt a device there needs to be a warrant for the contents, and it needs to be no doubt about the fact that it is indeed your device. So it needs to be a foregone conclusion that the device is yours, but only requires probable cause to believe that something specific and illegal is stored on the device.