Live data from Hacker News

Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer

signal.org

301–310 of 352 posts

Re: Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer

#301

Earlier quoted context omitted.

I don’t think that’s true. There’s a legal idea of “fruit of the poisonous tree”[0] that basically says you can’t use bad evidence, either in court or as an excuse to collect more, valid evidence. The defense attorney would say “if it hadn’t been for that completely untrustworthy Cellebrite evidence, the police wouldn’t have been able to get that search warrant they used to find the gun at his house, so we want that…

> I don’t think that’s true. There’s a legal idea of “fruit of the poisonous tree”[0] that basically says you can’t use bad evidence, either in court or as an excuse to collect more, valid evidence. I think the police have been using "parallel construction" to get around that for some time. https://en.wikipedia.org/wiki/Parallel_construction > Parallel construction is a law enforcement process of building a parallel,…

While I'm sure it happens, I don't think that "evidence laundering" is particularly common, especially at the federal level. Cases I ran required an "initial notification" that succinctly described how our agents were notified of the potential criminal activity. The fear of having a case thrown out, or being turned down months into a high-level investigation because an attorney is uncomfortable with the likely outcome, is huge in ensuring a valid investigation is run.

Now, that's not to say that cops wouldn't do this in order to finally get a case around a particular subject who was able to sidestep previous investigations or something. I just doubt that it happens often enough to be worthwhile.

Re: Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer

#302
post #300

Earlier quoted context omitted.

They don't have to read that. The defense lawyers have to read it, and the people in law enforcement need to read the cases where judges throw out Cellebrite evidence based on that.

The problem with that is the cases would need to get to the discovery stage. 95% of all criminal cases in the US are Plead out largely because the defendant can not afford competent legal representation This is why all kinds of questionable investigative tactics are still used even some that have clearly been ruled unconstitutional, they know most of the time it will not matter, they just need to get enough to make a…

Do all defendants not have the right to an attorney in criminal cases?

If evidence is obviously (or with high chance) disputable, then it puts pressure even in those cases where the attorney recommends the defendant to eventually plead.

Or maybe the attorneys available to those who can't afford are just crap in general?

Re: Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer

#303

Earlier quoted context omitted.

A defense team would need to show that the report had indeed been spoiled with such an exploit as demonstrated by the Signal team. Just because the possibility exists doesn't mean it happened. If there is a significant evidence report from a cellebrite pull, it almost always means that it either successfully unlocked the device or acquired a full physical image or both. A report doesn't have to be generated by PA. A…

Correct! Plus, most law enforcement seizes the device and keeps it until after the trial. If there were valid arguments against the authenticity of data in the extraction report, it would be easy to verify that data's existence by checking the phone, re-extracting the data using a known-clean UFED, etc. This isn't the end of the world by any means for legal mobile device searches.

Except that if the device is compromised, it could have changed the data on the phone. The phone, as evidence, can't be trusted anymore.

Re: Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer

#304

To be fair, this vulnerability disclosure is worthless, because it wasn’t actually disclosed—the true vulnerability is purported to be in the file that Signal uses to execute arbitrary code, of which the details are not shared. We are relying on pure trust that the video demonstration of the purported vulnerability is not a forgery. Additionally, I see from the video that the purported vulnerability is present in UFE…

The post seems to provide a straight-forward map to at least one vulnerability. If they have FFMPEG DDLs that have not been updated since 2012 and they are used on files found on the file system, you just need to find a relevant vulnerability and craft an appropriate media file. These vulnerabilities are well-known and well-documented. It just doesn't point to the specific DLL & CVE, but otherwise seems like it would be relatively easy to figure out.

Re: Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer

#306
post #300

Earlier quoted context omitted.

The problem with that is the cases would need to get to the discovery stage. 95% of all criminal cases in the US are Plead out largely because the defendant can not afford competent legal representation This is why all kinds of questionable investigative tactics are still used even some that have clearly been ruled unconstitutional, they know most of the time it will not matter, they just need to get enough to make a…

Do all defendants not have the right to an attorney in criminal cases? If evidence is obviously (or with high chance) disputable, then it puts pressure even in those cases where the attorney recommends the defendant to eventually plead. Or maybe the attorneys available to those who can't afford are just crap in general?

>>Do all defendants not have the right to an attorney in criminal cases?

In theory yes, but in most cases that will be a overworked lawyer that has 100's or 1000's of other active cases, and will not spend time other than negotiation the best deal.

Even if you happen to get a good public defender that has the ability to devote lots of time to your individual case, they would have no budget to hire an expert witness to present the vulnerabilities in the Cell-bright software to a jury

Your best bet would be if the ACLU or EFF took an interest in your case, but they take on very few cases relatively speaking and tend to focus on precedent setting cases, or cases that have high public interest (or can be made to have high public interest)

>Or maybe the attorneys available to those who can't afford are just crap in general?

In some cases they are incompetent, however in most cases they are just underfunded and massively over worked. In most jurisdictions the public defenders office is funded is 1/10 or less of what the prosecutors office is funded at.

Re: Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer

#307
post #55
post #23

Earlier quoted context omitted.

doesn't an itunes backup contain all the app data?

I own a Cellebrite, and yeah you are right. The Cellebrite box is nothing other than a phone backup tool. The nice thing it does is implement every backup sync protocol for every version of every mobile OS so you don't have to spend a whole day trying different combinations of iTunes and such. The "Physical Analyzer" is just a forensics tool. There are dozens of competitors out there that will take a phone and surfac…

I tried to use adb backup to backup my Chrome history/tabs, but it's empty because it has android:allowBackup=false. So unless they're also rooting the phone (which usually wipes the data) or have some 0-day privilege escalations, some apps can't be backed up this way.

Re: Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer

#308
While this report is entertaining to read, I have to wonder about possible downstream repercussions of the implications within the last paragraph; if you're in police custody or worse and your Signal app contains some 'aesthetically pleasing files' that interfere with the authoritarian software, it's likely going to be your ass on the line for all sorts of charges.

Don't get me wrong, the implication is enough to discredit Cellebrite, but my initial thoughts are that either this bluff gets called, or there's a non-zero risk of someone landing in even hotter water down the line for using Signal. Of course, this assumes that you're not already neck-deep for having encrypted data and upholding your right to privacy.

Re: Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer

#310

Earlier quoted context omitted.

Correct! Plus, most law enforcement seizes the device and keeps it until after the trial. If there were valid arguments against the authenticity of data in the extraction report, it would be easy to verify that data's existence by checking the phone, re-extracting the data using a known-clean UFED, etc. This isn't the end of the world by any means for legal mobile device searches.

Except that if the device is compromised, it could have changed the data on the phone. The phone, as evidence, can't be trusted anymore.

Signal never indicated this in the blog. They said that the phone would have a file that could be used to victimize the UFED PC after the extraction completes. It's plausible that the UFED could be infected post-extraction with malware that re-establishes a connection to the phone to infect it in reverse, but this is extremely unlikely and it would be easy to determine (assuming the UFED still exists and hasn't been meaningfully modified since the extraction.

For the UFED Touch, for example, the device runs the extraction and saved the result to a flash drive or external drive. This is then reviewed with the UFED software on another machine (laptop, desktop, whatever). What you're describing would mean that the extraction takes place (one-way. The Touch requests an ABD or iTunes backup process, phone responds with the backup files). The the malicious file in the backup pops and executes a command that runs software on the phone, thus infecting the phone with false data to cover the tracks and make the data on the report match the device. This is unreasonably complex, and I doubt any judge would accept it as enough to consider the data inadmissible. Let alone the fact that the data likely exists elsewhere in a verifiable way (Facebook Messenger, WhatsApp, Google Drive, etc), which the initial extraction results should give probable cause to the cops to obtain.

Post reply on HN