Live data from Hacker News

Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer

signal.org

251–260 of 352 posts

Re: Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer

#251

Earlier quoted context omitted.

> Apple may be legally required to at the very least, comment on this situation. "Required" to comment? By whom and for what reason?

Sending a cease and desist to Cellebrite for shipping their DLLs in their product I imagine. Obviously there may be some backchannel, but that is probably how it would go if you assume Apple and Cellebrite have no relationship.

Would they have a relationship? Cellebrite is an ant to Apple. Why would Apple risk credibility and security by helping them?

Re: Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer

#252

Earlier quoted context omitted.

signal wants to pick a fight with a grey company that gets money for cracking apps? not a good idea

They're already picking a fight with Cellebrite simply by existing, as Signal is antithetical to everything that Cellebrite stands for.

buying a safe != killing the guy thats invading your house

Re: Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer

#254

Earlier quoted context omitted.

I don’t think that’s true. There’s a legal idea of “fruit of the poisonous tree”[0] that basically says you can’t use bad evidence, either in court or as an excuse to collect more, valid evidence. The defense attorney would say “if it hadn’t been for that completely untrustworthy Cellebrite evidence, the police wouldn’t have been able to get that search warrant they used to find the gun at his house, so we want that…

> I don’t think that’s true. There’s a legal idea of “fruit of the poisonous tree”[0] that basically says you can’t use bad evidence, either in court or as an excuse to collect more, valid evidence. I think the police have been using "parallel construction" to get around that for some time. https://en.wikipedia.org/wiki/Parallel_construction > Parallel construction is a law enforcement process of building a parallel,…

[deleted]

Re: Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer

#256
post #72
post #7

This is truly a hacker’s retort. It attacks Cellebrite's ability to operate by casting doubt on the reports generated by the product that their customers may wish to use in court. It places them in legal peril from Apple, and removes any cover Apple would have to not take legal action. (I assume someone at Apple knew they were shipping their DLLs?) It makes a thinly-veiled threat that any random Signal user's data ma…

Cellebrite acquired BlackBag Technologies recently. BlackBag emerged from Apple's security team.

A little different from brown bag, in which the non-traceable payment travels under the table.

Re: Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer

#257
post #72

Earlier quoted context omitted.

Cellebrite acquired BlackBag Technologies recently. BlackBag emerged from Apple's security team.

A little different from brown bag, in which the non-traceable payment travels under the table.

Or dog shit under a door.

Re: Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer

#258

Wow, that video made my day. This bit is key: > "For example, by including a specially formatted but otherwise innocuous file in an app on a device that is then scanned by Cellebrite, it’s possible to execute code that modifies not just the Cellebrite report being created in that scan, but also all previous and future generated Cellebrite reports from all previously scanned devices and all future scanned devices in a…

[deleted]

Re: Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer

#259

Earlier quoted context omitted.

> It makes a thinly-veiled threat that any random Signal user's data may actively attempt to exploit their software in the future and demonstrates that it's trivial to do so. That does not make me feel good about Signal.

I've seen this reaction a few times. Can you say more? Presumably Signal users value privacy, and the implication is that when hacking tools used to violate that privacy are applied to a device running Signal, it may try to interfere and prevent the extraction to some degree. This seems like an ideal feature for a private messenger. In contrast, it would strike me as strange if a Signal user switched to another messe…

It's kind've hard to argue about having random unknown data laying around, but...

The insinuation that my device may be host to something potentially malicious is concerning. It gets a little worse that it can change, without notice. I'd tend to trust Signal and their security, but the potential for that mechanism to be hijacked is always present. They've certainly made it hard, though, and I think the folks at Signal are probably clever enough that my anemic observations don't tell the whole story.

Re: Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer

#260
> Also of interest, the installer for Physical Analyzer contains two bundled MSI installer packages named AppleApplicationsSupport64.msi and AppleMobileDeviceSupport6464.msi. These two MSI packages are digitally signed by Apple and appear to have been extracted from the Windows installer for iTunes version 12.9.0.167.

Couldn't Apple now sue Cellebrite?

Post reply on HN