Live data from Hacker News

Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer

signal.org

311–320 of 352 posts

Re: Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer

#311
post #309
post #277

"These two MSI packages are digitally signed by Apple" Couldn't Apple simply revoke the signature?

The digital signature is not needed to run the software.

The dll wil be flagged as malware in major av's if they revoked it

Re: Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer

#312
Something about this smells a little off.

If Moxie can get his hands on these devices and hack them, why can't Apple or Google, with all their resources, seem to be capable of REing them to fix the mobile device bugs they currently exploit?

Tinfoil hat perspective suggests they don't want to.

Re: Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer

#313
post #294

Earlier quoted context omitted.

That's literally what it is, except "get other evidence" means "construct a plausible story that gets you to the same point".

No, that's not the case here. You don't need a parallel construction in this example, because the UFED extraction (even if tainted by a similar exploit) wasn't illegally obtained.

Didn’t know that, thank you!

Re: Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer

#314
post #7

This is truly a hacker’s retort. It attacks Cellebrite's ability to operate by casting doubt on the reports generated by the product that their customers may wish to use in court. It places them in legal peril from Apple, and removes any cover Apple would have to not take legal action. (I assume someone at Apple knew they were shipping their DLLs?) It makes a thinly-veiled threat that any random Signal user's data ma…

Sadly I suspect the people in law enforcement who make purchasing decisions never read the Signal blog, and therefore all these points will be moot.

Good. They will then collect useless data that a lawyer will destroy in court.

Re: Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer

#315

Cellebrite's initial response[1] includes this gem "We have strict licensing policies that govern how customers are permitted to use our technology and do not sell to countries under sanction by the US, Israel or the broader international community." And these policies are obviously quite effective at preventing such uses. [1] https://www.theregister.com/2021/04/21/signal_cellebrite/

ah. Those must also be modules that fell from the truck.... (these companies clearly have trucks like sieves) I have no doubt that already, cellebrite are on the phone ordering more secure, err 'trucks'

Re: Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer

#316

Earlier quoted context omitted.

Post is here and let folks take a look.

Really REALLY bad idea - this is one of law enforcement's larger pet gadgets and companies, so the GP would not only have a particularly enthusiastic mob coming after them, said mob's pitchforks would have automatic cannon launchers and EMPs and push-button-activated nunchucks and all kinds of other crazy things that aren't legal for standard-issue pitchforks. So if the database is fingerprintable to the GP specifica…

I think it's a fair guess that a security researcher like that knows how to post on hn without leaving their home address. It's not particularly difficult.

Re: Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer

#317

Earlier quoted context omitted.

You either will have to come up with a plausible (literally, 'warranted') way to have gotten that data in the real world without relying on the data on the phone as the reason you went looking, or it will likely be thrown out due to it being "Fruit of the poisonous tree".

False data isn't FOTPT. If I search a phone with a tainted UFED and get a conversation between Bob (my subject) and Carl (his friend) about the drugs they're selling, that conversation either exists or doesn't exist. Now, let's assume that the court won't accept this evidence, based on a defense argument that it should be inadmissible after seeing the vulnerabilities of UFED, as detailed by Signal. The next investiga…

In your example, it's true that you could question Carl, but the a warrant to search Carl based on the false data should be overturned later.

Re: Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer

#318

Earlier quoted context omitted.

If they ignore cellebrite using their stuff they may have waived their right to be upset about someone else doing the same thing.

Copyright law isn't the same thing as Trademark law. Copyrights don't expire because the rightsholder failed to enforce their rights, only trademarks do.

Vigilantibus non dormientibus aequitas subvenit.

The principles of laches may still apply and provide a defence for Cellebrite if Apple makes an "unreasonable delay".

Re: Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer

#319
post #4

Earlier quoted context omitted.

I wonder if the intention here is to deter Cellebrite from parsing Signal files? Or to pressure them into fixing their security vulnerabilities?

Signal should generalise this into a library so that other app vendors can include these perfectly cromulant files

I imagine many brother app vendors, who may or may not maintain good relationships with Signal might possibly have found a usb drive containing the relevant data on the street. (pure speculation, i don't know anything about moxie, but judging by his tone, i wouldn't be shocked)

Re: Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer

#320
post #132
post #116

Earlier quoted context omitted.

The vulnerability claimed here doesn't necessarily crash the computer running the software. It runs arbitrary code, and said code is able to modify the data Cellebrite extracts. It is not clear whether it is possible to detect whether data collected in the past is compromised. There may be mitigations, but without knowing the full details of the exploit, it sounds a lot like reasonable doubt to me. A good lawyer woul…

If the data is off on another server, it seems unlikely that past cases can be compromised. There are a whole set of rules about challenging evidence, including electronic evidence. Keep in mind that the other side gets a crack at it also. It is unlikely that the whole case would be thrown out because of a corrupted file. Reasonable doubt is not part of the forensic process--this is what a jury needs to consider to r…

> If the data is off on another server, it seems unlikely that past cases can be compromised.

That isn't the point being made here. The data could have been compromised at the point of when it was gathered, not any time later.

Post reply on HN