Live data from Hacker News

Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer

signal.org

271–280 of 352 posts

Re: Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer

#272
How do Cellebrite maintain "Chain of custody"? If they need to modify (hack) the device to get access. I was of the understanding, that if any file is modified then "chain of custody" is no longer in good standing, and therefore cannot be used as evidence.

Re: Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer

#273

Earlier quoted context omitted.

I've seen this reaction a few times. Can you say more? Presumably Signal users value privacy, and the implication is that when hacking tools used to violate that privacy are applied to a device running Signal, it may try to interfere and prevent the extraction to some degree. This seems like an ideal feature for a private messenger. In contrast, it would strike me as strange if a Signal user switched to another messe…

It's kind've hard to argue about having random unknown data laying around, but... The insinuation that my device may be host to something potentially malicious is concerning. It gets a little worse that it can change, without notice. I'd tend to trust Signal and their security, but the potential for that mechanism to be hijacked is always present. They've certainly made it hard, though, and I think the folks at Signa…

> The insinuation that my device may be host to something potentially malicious is concerning. It gets a little worse that it can change, without notice.

Do you use an iPhone or a phone with Google Play Services on it?

Those both have the technical capability of receiving targeted updates.

Re: Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer

#274

Earlier quoted context omitted.

IANAL, and I don't speak for Apple, but as far as I can tell, the part about Apple is nonsense. CoreFoundation is open source: https://github.com/opensource-apple/CF libdispatch is open source: https://apple.github.io/swift-corelibs-libdispatch/post/libd... ASL is open source: https://opensource.apple.com/source/syslog/syslog-349.1.1/li... The objective C runtime is open source: https://github.com/opensource-apple/ob…

Yes, but the copy shipped is signed by Apple. i.e. they did not compile their own copy.

> signed by Apple

Signed by Apple's key!

Re: Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer

#275

Earlier quoted context omitted.

I've seen this reaction a few times. Can you say more? Presumably Signal users value privacy, and the implication is that when hacking tools used to violate that privacy are applied to a device running Signal, it may try to interfere and prevent the extraction to some degree. This seems like an ideal feature for a private messenger. In contrast, it would strike me as strange if a Signal user switched to another messe…

It's kind've hard to argue about having random unknown data laying around, but... The insinuation that my device may be host to something potentially malicious is concerning. It gets a little worse that it can change, without notice. I'd tend to trust Signal and their security, but the potential for that mechanism to be hijacked is always present. They've certainly made it hard, though, and I think the folks at Signa…

Everyone can inspect the Signal app's source code, though, and make sure that nothing funny is happening with the "aesthetically pleasing" files it downloads.

Re: Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer

#276

Earlier quoted context omitted.

It's kind've hard to argue about having random unknown data laying around, but... The insinuation that my device may be host to something potentially malicious is concerning. It gets a little worse that it can change, without notice. I'd tend to trust Signal and their security, but the potential for that mechanism to be hijacked is always present. They've certainly made it hard, though, and I think the folks at Signa…

> The insinuation that my device may be host to something potentially malicious is concerning. It gets a little worse that it can change, without notice. Do you use an iPhone or a phone with Google Play Services on it? Those both have the technical capability of receiving targeted updates.

Not just that. In the case of Google Play Services, SafetyNet also downloads random binary blobs from Google and executes them as root. Makes me feel a lot… safer about my phone.

Re: Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer

#279

Earlier quoted context omitted.

Sadly I suspect the people in law enforcement who make purchasing decisions never read the Signal blog, and therefore all these points will be moot.

They don't have to read that. The defense lawyers have to read it, and the people in law enforcement need to read the cases where judges throw out Cellebrite evidence based on that.

This.

Re: Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer

#280
post #230

Earlier quoted context omitted.

You either will have to come up with a plausible (literally, 'warranted') way to have gotten that data in the real world without relying on the data on the phone as the reason you went looking, or it will likely be thrown out due to it being "Fruit of the poisonous tree".

That's precisely what parallel construction is: a lie told by investigators to the court to sidestep the poison tree, bolstered by real evidence specifically gathered to lie outside of the branches of same. It's a method that crooked law enforcement uses to deceive courts. It's so common as to have its own name now.

Right, but that implies you can construct an entire chain that doesn't include checking their phone. Just pointing out, per the post i was replying to, it's not simply use the phone, get other evidence, don't worry about the phone's evidence being thrown out.
Post reply on HN