Live data from Hacker News

Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer

signal.org

321–330 of 352 posts

Re: Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer

#321

Earlier quoted context omitted.

False data isn't FOTPT. If I search a phone with a tainted UFED and get a conversation between Bob (my subject) and Carl (his friend) about the drugs they're selling, that conversation either exists or doesn't exist. Now, let's assume that the court won't accept this evidence, based on a defense argument that it should be inadmissible after seeing the vulnerabilities of UFED, as detailed by Signal. The next investiga…

In your example, it's true that you could question Carl, but the a warrant to search Carl based on the false data should be overturned later.

It's not knowingly false, so the warrant would remain valid.

Re: Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer

#322

Earlier quoted context omitted.

The optimal thing for them to do would be to build the framework and ship partially corrupted JPEGs that don't actually do anything nasty to Cellebrite. Cellebrite can verify that the machinery is there (not a totally idle threat) but no one can prove that Signal has actually done anything illegal. Cellebrite then wastes a bunch of times gathering and analyzing the files without actually learning anything from it. Th…

Even if Signal put the files out there and explicitly owned up to it, I struggle to see how it could be even remotely illegal. It's not their fault some other company's faulty product falls apart when it hits bad data in their app.

Agreed. Obviously, I'm not a lawyer so who knows. But it seems ridiculous that you could break into someone else's device and run all of their files and then come after them legally because a file you effectively stole didn't run properly on your computer.

At some point if someone breaks through multiple levels of advanced security to, say, steal your gun and then shoot themselves in the face with it, whose fault is that really...

Re: Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer

#323

Earlier quoted context omitted.

well, close enough for me.

/u/hprotagonist - I've always thought you had the best username on HN, for what it's worth!

i'm consistently amazed it was available.

Re: Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer

#324

Truly a jaw dropping blog post, as the top comment currently states, Apple may be legally required to at the very least, comment on this situation.

> Apple may be legally required to at the very least, comment on this situation. "Required" to comment? By whom and for what reason?

>"Required" to comment? By whom and for what reason?

By stockowners who might not like their valuable IP used in this way or by this company without permission?

Re: Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer

#325

Earlier quoted context omitted.

I found that funny too. It sounds to me like a good way to end up with the device to analyze without being constrained by a contract or EULA prohibiting it.

Yes, it's known as a euphemism. TFA just took the joke to hilarious extremes with the photos. https://www.phrases.org.uk/meanings/fell-off-the-back-of-a-t...

TFA? I know you're referring to Moxie (somehow) but I can't figure out the acronym.

Re: Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer

#326
post #325

Earlier quoted context omitted.

Yes, it's known as a euphemism. TFA just took the joke to hilarious extremes with the photos. https://www.phrases.org.uk/meanings/fell-off-the-back-of-a-t...

TFA? I know you're referring to Moxie (somehow) but I can't figure out the acronym.

IIRC "The Fucking Article". I think the expletive originally was because people "wouldn't read TFA", but eventually it just kinda became the way to refer to the article linked from a Hacker News thread.

Re: Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer

#327
post #325

Earlier quoted context omitted.

TFA? I know you're referring to Moxie (somehow) but I can't figure out the acronym.

IIRC "The Fucking Article". I think the expletive originally was because people "wouldn't read TFA", but eventually it just kinda became the way to refer to the article linked from a Hacker News thread.

Oooh of course! Thanks!

Re: Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer

#328
post #316

Earlier quoted context omitted.

Really REALLY bad idea - this is one of law enforcement's larger pet gadgets and companies, so the GP would not only have a particularly enthusiastic mob coming after them, said mob's pitchforks would have automatic cannon launchers and EMPs and push-button-activated nunchucks and all kinds of other crazy things that aren't legal for standard-issue pitchforks. So if the database is fingerprintable to the GP specifica…

I think it's a fair guess that a security researcher like that knows how to post on hn without leaving their home address. It's not particularly difficult.

Well this would also require him to have been properly anonymous when reporting the bugs last year.

Re: Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer

#329

Earlier quoted context omitted.

Sadly I suspect the people in law enforcement who make purchasing decisions never read the Signal blog, and therefore all these points will be moot.

They don't have to read that. The defense lawyers have to read it, and the people in law enforcement need to read the cases where judges throw out Cellebrite evidence based on that.

That won't do much. In order to throw the evidence out, it needs to be shown that something was actually compromised by the tool, not just that it is possible.

Consider https://www.securityweek.com/forensics-tool-flaw-allows-hack.... Have any cases been thrown out? I don't think so.

Re: Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer

#330
Signal have just added files to compromise Cellebrite to their default installation !

"In completely unrelated news, upcoming versions of Signal will be periodically fetching files to place in app storage.

These files are never used for anything inside Signal and never interact with Signal software or data, but they look nice, and aesthetics are important in software.

Files will only be returned for accounts that have been active installs for some time already, and only probabilistically in low percentages based on phone number sharding.

We have a few different versions of files that we think are aesthetically pleasing, and will iterate through those slowly over time. There is no other significance to these files."

Post reply on HN