Earlier quoted context omitted.
> Apple may be legally required to at the very least, comment on this situation. "Required" to comment? By whom and for what reason?
Sending a cease and desist to Cellebrite for shipping their DLLs in their product I imagine. Obviously there may be some backchannel, but that is probably how it would go if you assume Apple and Cellebrite have no relationship.
Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer
251–260 of 352 posts
Re: Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer
#252Earlier quoted context omitted.
signal wants to pick a fight with a grey company that gets money for cracking apps? not a good idea
They're already picking a fight with Cellebrite simply by existing, as Signal is antithetical to everything that Cellebrite stands for.
Re: Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer
#253Re: Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer
#254Earlier quoted context omitted.
I don’t think that’s true. There’s a legal idea of “fruit of the poisonous tree”[0] that basically says you can’t use bad evidence, either in court or as an excuse to collect more, valid evidence. The defense attorney would say “if it hadn’t been for that completely untrustworthy Cellebrite evidence, the police wouldn’t have been able to get that search warrant they used to find the gun at his house, so we want that…
> I don’t think that’s true. There’s a legal idea of “fruit of the poisonous tree”[0] that basically says you can’t use bad evidence, either in court or as an excuse to collect more, valid evidence. I think the police have been using "parallel construction" to get around that for some time. https://en.wikipedia.org/wiki/Parallel_construction > Parallel construction is a law enforcement process of building a parallel,…
Re: Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer
#255Re: Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer
#256This is truly a hacker’s retort. It attacks Cellebrite's ability to operate by casting doubt on the reports generated by the product that their customers may wish to use in court. It places them in legal peril from Apple, and removes any cover Apple would have to not take legal action. (I assume someone at Apple knew they were shipping their DLLs?) It makes a thinly-veiled threat that any random Signal user's data ma…
Cellebrite acquired BlackBag Technologies recently. BlackBag emerged from Apple's security team.
Re: Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer
#257Re: Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer
#258Wow, that video made my day. This bit is key: > "For example, by including a specially formatted but otherwise innocuous file in an app on a device that is then scanned by Cellebrite, it’s possible to execute code that modifies not just the Cellebrite report being created in that scan, but also all previous and future generated Cellebrite reports from all previously scanned devices and all future scanned devices in a…
Re: Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer
#259Earlier quoted context omitted.
> It makes a thinly-veiled threat that any random Signal user's data may actively attempt to exploit their software in the future and demonstrates that it's trivial to do so. That does not make me feel good about Signal.
I've seen this reaction a few times. Can you say more? Presumably Signal users value privacy, and the implication is that when hacking tools used to violate that privacy are applied to a device running Signal, it may try to interfere and prevent the extraction to some degree. This seems like an ideal feature for a private messenger. In contrast, it would strike me as strange if a Signal user switched to another messe…
The insinuation that my device may be host to something potentially malicious is concerning. It gets a little worse that it can change, without notice. I'd tend to trust Signal and their security, but the potential for that mechanism to be hijacked is always present. They've certainly made it hard, though, and I think the folks at Signal are probably clever enough that my anemic observations don't tell the whole story.
Re: Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer
#260Couldn't Apple now sue Cellebrite?