Earlier quoted context omitted.
You either will have to come up with a plausible (literally, 'warranted') way to have gotten that data in the real world without relying on the data on the phone as the reason you went looking, or it will likely be thrown out due to it being "Fruit of the poisonous tree".
Sounds like a US/UK-centric view of things. There's many countries where evidence can be used in court regardless of how it was obtained, Swedish and Germany to name two.
Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer
281–290 of 352 posts
Re: Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer
#282Re: Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer
#283Earlier quoted context omitted.
I don’t think that’s true. There’s a legal idea of “fruit of the poisonous tree”[0] that basically says you can’t use bad evidence, either in court or as an excuse to collect more, valid evidence. The defense attorney would say “if it hadn’t been for that completely untrustworthy Cellebrite evidence, the police wouldn’t have been able to get that search warrant they used to find the gun at his house, so we want that…
Even if parallel construction wouldn't exist, in Germany, for example, illegally obtained evidence is still valid in court.
In the Metzler kidnapping case the first confession was not admissible in court which had been obtained under threat of torture.
Re: Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer
#284Earlier quoted context omitted.
This indeed looks like a FUD statement, implying that they can have an infinite amount of potential vulnerabilities. Realistically though, writing parsers that do not yield control of your whole device is not that complex. The people exploiting iOS zero days can certainly do it.
But it might be easier for Cellebrite to just stop exfiltrating data from Signal. Of course, other apps could discover similar vulnerabilities.
I think this taints any phone having Signal installed.
Re: Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer
#285> Also of interest, the installer for Physical Analyzer contains two bundled MSI installer packages named AppleApplicationsSupport64.msi and AppleMobileDeviceSupport6464.msi. These two MSI packages are digitally signed by Apple and appear to have been extracted from the Windows installer for iTunes version 12.9.0.167. Couldn't Apple now sue Cellebrite?
Yup, Signal just handed Apple's lawyers a loaded gun. Who knew I'd be enjoying Signal and Apple tag-teaming Cellebrite.
Re: Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer
#286Earlier quoted context omitted.
Damn, a chain of custody where the thing in evidence is also part of not only its own chain but also those of other evidence acquired afterwards? I can't imagine what kind of case law exists around that, but I'm sure it's hilarious!
> also those of other evidence acquired afterwards And prior extracts on the device.
Re: Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer
#287Re: Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer
#288Re: Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer
#289Earlier quoted context omitted.
Sadly I suspect the people in law enforcement who make purchasing decisions never read the Signal blog, and therefore all these points will be moot.
They don't have to read that. The defense lawyers have to read it, and the people in law enforcement need to read the cases where judges throw out Cellebrite evidence based on that.
Re: Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer
#290Earlier quoted context omitted.
To me it seems more like the equivalent of leaving booby trapped packages to be found by porch pirates. Or putting laxatives (or worse) in your sandwich to get back at the unknown coworker stealing your lunch. Both of which are considered illegal in the US. Assuming these files actually contain exploits. Maybe they do maybe they don't. You feeling lucky Cellebrite?
The question of whether damaging reports would be illegal is separate from whether booby traps are illegal. And they're not, in the broad case: Booby trapped packages are only illegal if they cause bodily harm or damage or are negligent along those lines.