Earlier quoted context omitted.
False data isn't FOTPT. If I search a phone with a tainted UFED and get a conversation between Bob (my subject) and Carl (his friend) about the drugs they're selling, that conversation either exists or doesn't exist. Now, let's assume that the court won't accept this evidence, based on a defense argument that it should be inadmissible after seeing the vulnerabilities of UFED, as detailed by Signal. The next investiga…
In your example, it's true that you could question Carl, but the a warrant to search Carl based on the false data should be overturned later.
Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer
321–330 of 352 posts
Re: Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer
#322Earlier quoted context omitted.
The optimal thing for them to do would be to build the framework and ship partially corrupted JPEGs that don't actually do anything nasty to Cellebrite. Cellebrite can verify that the machinery is there (not a totally idle threat) but no one can prove that Signal has actually done anything illegal. Cellebrite then wastes a bunch of times gathering and analyzing the files without actually learning anything from it. Th…
Even if Signal put the files out there and explicitly owned up to it, I struggle to see how it could be even remotely illegal. It's not their fault some other company's faulty product falls apart when it hits bad data in their app.
At some point if someone breaks through multiple levels of advanced security to, say, steal your gun and then shoot themselves in the face with it, whose fault is that really...
Re: Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer
#323Re: Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer
#324Truly a jaw dropping blog post, as the top comment currently states, Apple may be legally required to at the very least, comment on this situation.
> Apple may be legally required to at the very least, comment on this situation. "Required" to comment? By whom and for what reason?
By stockowners who might not like their valuable IP used in this way or by this company without permission?
Re: Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer
#325Earlier quoted context omitted.
I found that funny too. It sounds to me like a good way to end up with the device to analyze without being constrained by a contract or EULA prohibiting it.
Yes, it's known as a euphemism. TFA just took the joke to hilarious extremes with the photos. https://www.phrases.org.uk/meanings/fell-off-the-back-of-a-t...
Re: Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer
#326Earlier quoted context omitted.
Yes, it's known as a euphemism. TFA just took the joke to hilarious extremes with the photos. https://www.phrases.org.uk/meanings/fell-off-the-back-of-a-t...
TFA? I know you're referring to Moxie (somehow) but I can't figure out the acronym.
Re: Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer
#327Earlier quoted context omitted.
TFA? I know you're referring to Moxie (somehow) but I can't figure out the acronym.
IIRC "The Fucking Article". I think the expletive originally was because people "wouldn't read TFA", but eventually it just kinda became the way to refer to the article linked from a Hacker News thread.
Re: Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer
#328Earlier quoted context omitted.
Really REALLY bad idea - this is one of law enforcement's larger pet gadgets and companies, so the GP would not only have a particularly enthusiastic mob coming after them, said mob's pitchforks would have automatic cannon launchers and EMPs and push-button-activated nunchucks and all kinds of other crazy things that aren't legal for standard-issue pitchforks. So if the database is fingerprintable to the GP specifica…
I think it's a fair guess that a security researcher like that knows how to post on hn without leaving their home address. It's not particularly difficult.
Re: Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer
#329Earlier quoted context omitted.
Sadly I suspect the people in law enforcement who make purchasing decisions never read the Signal blog, and therefore all these points will be moot.
They don't have to read that. The defense lawyers have to read it, and the people in law enforcement need to read the cases where judges throw out Cellebrite evidence based on that.
Consider https://www.securityweek.com/forensics-tool-flaw-allows-hack.... Have any cases been thrown out? I don't think so.
Re: Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer
#330"In completely unrelated news, upcoming versions of Signal will be periodically fetching files to place in app storage.
These files are never used for anything inside Signal and never interact with Signal software or data, but they look nice, and aesthetics are important in software.
Files will only be returned for accounts that have been active installs for some time already, and only probabilistically in low percentages based on phone number sharding.
We have a few different versions of files that we think are aesthetically pleasing, and will iterate through those slowly over time. There is no other significance to these files."