Live data from Hacker News

Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer

signal.org

291–300 of 352 posts

Re: Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer

#291

Earlier quoted context omitted.

The end of the post is extremely specifically and carefully not describing a framework for rolling out files to exploit these vulnerabilities; those files as described do nothing, and serve only aesthetic purposes. While it's easy to read that as a wink that they are exploiting the vulnerabilities they found while maintaining plausible deniability that they aren't, it's equally possible it's the other way around: the…

The optimal thing for them to do would be to build the framework and ship partially corrupted JPEGs that don't actually do anything nasty to Cellebrite. Cellebrite can verify that the machinery is there (not a totally idle threat) but no one can prove that Signal has actually done anything illegal. Cellebrite then wastes a bunch of times gathering and analyzing the files without actually learning anything from it. Th…

Even if Signal put the files out there and explicitly owned up to it, I struggle to see how it could be even remotely illegal. It's not their fault some other company's faulty product falls apart when it hits bad data in their app.

Re: Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer

#292
post #128
post #89

Earlier quoted context omitted.

It's about casting doubt on their software and it's trustworthyness. In computer forensics it's ALL about being able to verify, without a shadow of doubt that something is what they say it is. Chain of custody rules everything. This blasts a huge gaping hole in all that. He's proven that chain of custody can be tampered with and undetected. Files can be planted, altered or erased. Reports can altered. Timestamps can…

> In computer forensics it's ALL about being able to verify, without a shadow of doubt that something is what they say it is Mostly. The other side gets all the evidence that the opposing side sees. They both get a chance to review it. > Chain of custody rules everything. Agree. > This blasts a huge gaping hole in all that. Not really. The analysis goes in two steps. One is to pull all the data from the phone, in a c…

By mearly backing up phone with cellebrite it may run exploits.

Exploits may fuck up phone, backup and even cellebrite host os.

As such, phone, backed up data and reports are useless going forward.

Re: Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer

#293

Earlier quoted context omitted.

Sure, but the data on the phone will lead you to evidence in the real world, which will be meaningful proof that can be used in court.

You either will have to come up with a plausible (literally, 'warranted') way to have gotten that data in the real world without relying on the data on the phone as the reason you went looking, or it will likely be thrown out due to it being "Fruit of the poisonous tree".

https://www.reuters.com/article/us-dea-sod/exclusive-u-s-dir...

~~~ The undated documents show that federal agents are trained to “recreate” the investigative trail to effectively cover up where the information originated, a practice that some experts say violates a defendant’s Constitutional right to a fair trial. If defendants don’t know how an investigation began, they cannot know to ask to review potential sources of exculpatory evidence - information that could reveal entrapment, mistakes or biased witnesses. ~~~

If you believe any of "fruit of the poisonous tree" stuff makes any difference, I've got a bridge to sell you. There is clear evidence that DEA agents are trained to create a "clean" story of evidence around the illicit information they get.

Re: Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer

#294
post #230

Earlier quoted context omitted.

That's precisely what parallel construction is: a lie told by investigators to the court to sidestep the poison tree, bolstered by real evidence specifically gathered to lie outside of the branches of same. It's a method that crooked law enforcement uses to deceive courts. It's so common as to have its own name now.

Right, but that implies you can construct an entire chain that doesn't include checking their phone. Just pointing out, per the post i was replying to, it's not simply use the phone, get other evidence, don't worry about the phone's evidence being thrown out.

That's literally what it is, except "get other evidence" means "construct a plausible story that gets you to the same point".

Re: Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer

#295

Earlier quoted context omitted.

Sure, but the data on the phone will lead you to evidence in the real world, which will be meaningful proof that can be used in court.

You either will have to come up with a plausible (literally, 'warranted') way to have gotten that data in the real world without relying on the data on the phone as the reason you went looking, or it will likely be thrown out due to it being "Fruit of the poisonous tree".

False data isn't FOTPT.

If I search a phone with a tainted UFED and get a conversation between Bob (my subject) and Carl (his friend) about the drugs they're selling, that conversation either exists or doesn't exist. Now, let's assume that the court won't accept this evidence, based on a defense argument that it should be inadmissible after seeing the vulnerabilities of UFED, as detailed by Signal.

The next investigative step in to go interview and search Carl, since there is probable cause to believe that a conversation occurred about their drug dealing on his phone. Unless I a) know my UFED is vulnerable and b) have reason to believe the text conversation between Bob and Carl is fake, my warrant for Carl's phone is valid. Now, I search Carl's phone with the same UFED and find the exact same conversation.

At this point, it's still possible for the UFED to have made the conversation up on both sides and for both extractions, and this would probably make the resulting conversation (and potentially everything in the report) inadmissible, but any admissions from Bob or Carl, including based on questions asked about the conversation itself, would still be admissible. I could show the report to Bob and Carl as evidence against them and get a confession, which would be admissible. Additionally, if the court determines that the UFED report is inadmissible based on the potentially for it to be forensically unsound, I would still have the phones themselves. UFED (except in rare circumstances) requires the phone to be unlocked before it can make its extraction. As such, I could manually browse the phone to the conversation in question and take photos of the phone with the real conversations between Bob and Carl. I could also verify through an ISP/messenger app that evidence of those conversations occurred (for example, metadata demonstrating matching times and message sizes that align with the potentially-fabricated message).

The FOTPT defense only applies to illegally obtained evidence. Assuming you obtained a valid warrant or consent to conduct the search, there was nothing illegal about the UFED extraction that would make the FOTPT defense applicable.

Re: Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer

#296
post #293

Earlier quoted context omitted.

You either will have to come up with a plausible (literally, 'warranted') way to have gotten that data in the real world without relying on the data on the phone as the reason you went looking, or it will likely be thrown out due to it being "Fruit of the poisonous tree".

https://www.reuters.com/article/us-dea-sod/exclusive-u-s-dir... ~~~ The undated documents show that federal agents are trained to “recreate” the investigative trail to effectively cover up where the information originated, a practice that some experts say violates a defendant’s Constitutional right to a fair trial. If defendants don’t know how an investigation began, they cannot know to ask to review potential source…

It doesn't matter. This story/example from Signal has nothing to do with FOTPT.

Re: Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer

#297
post #294

Earlier quoted context omitted.

Right, but that implies you can construct an entire chain that doesn't include checking their phone. Just pointing out, per the post i was replying to, it's not simply use the phone, get other evidence, don't worry about the phone's evidence being thrown out.

That's literally what it is, except "get other evidence" means "construct a plausible story that gets you to the same point".

No, that's not the case here. You don't need a parallel construction in this example, because the UFED extraction (even if tainted by a similar exploit) wasn't illegally obtained.

Re: Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer

#298

Earlier quoted context omitted.

All that trouble becaused a bag conveniently "fell from a truck". All in all I'm really happy for all this.

I am happy to see the bag survived its most untimely truck tumble while remaining a e s t h e t i c a l l y - - - p l e a s i n g.

What a sturdy bag it is!

Re: Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer

#299

Earlier quoted context omitted.

I don’t think that’s true. There’s a legal idea of “fruit of the poisonous tree”[0] that basically says you can’t use bad evidence, either in court or as an excuse to collect more, valid evidence. The defense attorney would say “if it hadn’t been for that completely untrustworthy Cellebrite evidence, the police wouldn’t have been able to get that search warrant they used to find the gun at his house, so we want that…

A defense team would need to show that the report had indeed been spoiled with such an exploit as demonstrated by the Signal team. Just because the possibility exists doesn't mean it happened. If there is a significant evidence report from a cellebrite pull, it almost always means that it either successfully unlocked the device or acquired a full physical image or both. A report doesn't have to be generated by PA. A…

Correct!

Plus, most law enforcement seizes the device and keeps it until after the trial. If there were valid arguments against the authenticity of data in the extraction report, it would be easy to verify that data's existence by checking the phone, re-extracting the data using a known-clean UFED, etc. This isn't the end of the world by any means for legal mobile device searches.

Re: Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer

#300

Earlier quoted context omitted.

Sadly I suspect the people in law enforcement who make purchasing decisions never read the Signal blog, and therefore all these points will be moot.

They don't have to read that. The defense lawyers have to read it, and the people in law enforcement need to read the cases where judges throw out Cellebrite evidence based on that.

The problem with that is the cases would need to get to the discovery stage.

95% of all criminal cases in the US are Plead out largely because the defendant can not afford competent legal representation

This is why all kinds of questionable investigative tactics are still used even some that have clearly been ruled unconstitutional, they know most of the time it will not matter, they just need to get enough to make an arrest, the system will destroy the person anyway no conviction needed, and most likely the person will plead guilty even if innocent just to make the abuse stop

Post reply on HN