Live data from Hacker News

Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer

signal.org

261–270 of 352 posts

Re: Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer

#261

> Also of interest, the installer for Physical Analyzer contains two bundled MSI installer packages named AppleApplicationsSupport64.msi and AppleMobileDeviceSupport6464.msi. These two MSI packages are digitally signed by Apple and appear to have been extracted from the Windows installer for iTunes version 12.9.0.167. Couldn't Apple now sue Cellebrite?

Yup, Signal just handed Apple's lawyers a loaded gun. Who knew I'd be enjoying Signal and Apple tag-teaming Cellebrite.

Re: Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer

#262

Earlier quoted context omitted.

Sure, but the data on the phone will lead you to evidence in the real world, which will be meaningful proof that can be used in court.

You either will have to come up with a plausible (literally, 'warranted') way to have gotten that data in the real world without relying on the data on the phone as the reason you went looking, or it will likely be thrown out due to it being "Fruit of the poisonous tree".

Sounds like a US/UK-centric view of things. There's many countries where evidence can be used in court regardless of how it was obtained, Swedish and Germany to name two.

Re: Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer

#264

Earlier quoted context omitted.

Is it malware if users desire for their devices to be resistant to surveillance tools?

Those are not related issues - it's malware or not malware based on what it does or did (e.g. did it corrupt data on someone else's computer system because it was intended to do just that thing?) regardless of the reason for placing it there. If you can't figure out a way to satisfy your desire for your devices to be resistant to surveillance tools with legal means, well, then you can't satisfy that desire. Furthermo…

> If you can't figure out a way to satisfy your desire for your devices to be resistant to surveillance tools with legal means, well, then you can't satisfy that desire.

I fear this part of your argument is fallacious. A peaceful and hilarious response to an abuse is not illegal. An if it is, it should not be. This post just highlights how petty the means and methods used by "some companies" are. Moxie is rightfully mocking Cellebrite and its customers, and it's fantastic.

About the obstruction of justice... If governments around the world are having an appetite for abuses, we shall not fall for it. There are other ways to get to criminals. Tell state officers they can do their job without abusing the private sphere of citizens.

It's Cellebrite devices that should be made illegal, because "justice" should not depend on surveillance tools. Just days ago the same US IC shared a memo/report about the rise of authoritarianism and how western democracies are threatened by it. Let's stop this double standard.

Re: Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer

#265

Earlier quoted context omitted.

the cellebrite ambassador we talked to (as private company) basically bragged they were the ones that unlocked the San Bernadirno iPhone. I'm sure towards government officials and Law Enforcement they brag even more.

But they weren’t, that was Azimuth: https://www.washingtonpost.com/technology/2021/04/14/azimuth...

Hm, interesting. So there are articles saying it's Cellebrite https://www.reuters.com/article/us-apple-encryption-cellebri..., then others saying it was unmentioned professional hackers and then your article where all three possibilities are mentioned.

Re: Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer

#266

Earlier quoted context omitted.

They're already picking a fight with Cellebrite simply by existing, as Signal is antithetical to everything that Cellebrite stands for.

buying a safe != killing the guy thats invading your house

I think this would be more like including exploding dye packs in your bags of money.

Re: Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer

#267
post #128
post #89

Earlier quoted context omitted.

It's about casting doubt on their software and it's trustworthyness. In computer forensics it's ALL about being able to verify, without a shadow of doubt that something is what they say it is. Chain of custody rules everything. This blasts a huge gaping hole in all that. He's proven that chain of custody can be tampered with and undetected. Files can be planted, altered or erased. Reports can altered. Timestamps can…

> In computer forensics it's ALL about being able to verify, without a shadow of doubt that something is what they say it is Mostly. The other side gets all the evidence that the opposing side sees. They both get a chance to review it. > Chain of custody rules everything. Agree. > This blasts a huge gaping hole in all that. Not really. The analysis goes in two steps. One is to pull all the data from the phone, in a c…

> As I understand it, the analysis portion is where things can explode.

This very blog post says they have found similar vulnerabilities in both steps.

Re: Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer

#268
post #102

Earlier quoted context omitted.

They are not putting malware into their app. They are adding athletically pleasing files to their app. Is it Signals fault if someone else's software doesn't work properly with them? How can Signal test every piece of software to make sure it's compatible with their own software? Especially when the other software is using Signal in a unintended way. It's not signals job to secure 3rd party software, that's entirely…

Intent matters, come on, your arguments are ridiculuous. If one of the aesthetically pleasing files turns out to contain an exploit targeted at Cellebrite software, then it wouldn't be hard to convince a jury that this isn't a coincidence but intentional malware, especially combined with this wink-wink bragpost. It's not Signal's job to secure third party software, they can intentionally post incompatible data, but i…

Because Celebrite's software is shown to be exploitable, how do you know it was Signal's files and not someones else corrupting it?

Re: Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer

#269

Earlier quoted context omitted.

> At issue there is the "foregone conclusion" exception to the 5th amendment. The unclear part seems to be how strong the evidence needs to be that the device is yours and that the evidence is on there. In this case, his sister testified to both. But would it be strong enough with forensic evidence alone? Unclear. > As far as I understand things you've lost the case by that point anyway. Perhaps, but there may still…

> The unclear part seems to be how strong the evidence needs to be that the device is yours and that the evidence is on there. The 5th amendment protects you from having to testify against yourself, but it doesn't protect you from having to turn over incriminating evidence against yourself. The 4th amendment protects your stuff, but only up to the point of requiring probable cause for a warrant. At issue in these sor…

Thanks. That helps a lot to clarify.

Re: Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer

#270

Earlier quoted context omitted.

Sending a cease and desist to Cellebrite for shipping their DLLs in their product I imagine. Obviously there may be some backchannel, but that is probably how it would go if you assume Apple and Cellebrite have no relationship.

Would they have a relationship? Cellebrite is an ant to Apple. Why would Apple risk credibility and security by helping them?

Because Apple cares a lot about their security, and the perception of security, and they have a lot of lawyers with nasty teeth. Using stolen unlicensed Apple technology to hack people's iOS devices is like eating a bear cub in front of mama bear.
Post reply on HN