Live data from Hacker News

Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer

signal.org

331–340 of 352 posts

Re: Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer

#331
> Since almost all of Cellebrite’s code exists to parse untrusted input that could be formatted in an unexpected way to exploit memory corruption or other vulnerabilities in the parsing software, one might expect Cellebrite to have been extremely cautious. [...]

Yeah, but they probably figured they're not being attacked. But now? Now they'll have to figure they are.

Re: Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer

#332

Earlier quoted context omitted.

Signal should generalise this into a library so that other app vendors can include these perfectly cromulant files

I imagine many brother app vendors, who may or may not maintain good relationships with Signal might possibly have found a usb drive containing the relevant data on the street. (pure speculation, i don't know anything about moxie, but judging by his tone, i wouldn't be shocked)

hehe.

Now imagine if Hack Back laws actually passed... companies like Whisper Systems would have had impunity for even more shenanigans :)

Re: Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer

#333
post #307
post #55

Earlier quoted context omitted.

I own a Cellebrite, and yeah you are right. The Cellebrite box is nothing other than a phone backup tool. The nice thing it does is implement every backup sync protocol for every version of every mobile OS so you don't have to spend a whole day trying different combinations of iTunes and such. The "Physical Analyzer" is just a forensics tool. There are dozens of competitors out there that will take a phone and surfac…

I tried to use adb backup to backup my Chrome history/tabs, but it's empty because it has android:allowBackup=false. So unless they're also rooting the phone (which usually wipes the data) or have some 0-day privilege escalations, some apps can't be backed up this way.

I don't know much about Android so I can't help you, but it is much more likely that the company that employs dozens of mobile forensics and hardware engineers and has close relationships with Android device makers figured out a workaround.

Re: Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer

#334
post #327

Earlier quoted context omitted.

IIRC "The Fucking Article". I think the expletive originally was because people "wouldn't read TFA", but eventually it just kinda became the way to refer to the article linked from a Hacker News thread.

Oooh of course! Thanks!

Also can be "the fine article" when used in a non-antagonistic way!

I think it originated with "RTFM" which was an old unix admin way of saying read the fucking manual (or man page).

Re: Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer

#335
post #267
post #128

Earlier quoted context omitted.

> In computer forensics it's ALL about being able to verify, without a shadow of doubt that something is what they say it is Mostly. The other side gets all the evidence that the opposing side sees. They both get a chance to review it. > Chain of custody rules everything. Agree. > This blasts a huge gaping hole in all that. Not really. The analysis goes in two steps. One is to pull all the data from the phone, in a c…

> As I understand it, the analysis portion is where things can explode. This very blog post says they have found similar vulnerabilities in both steps.

If the data collection step can possibly be affected by things like media file exploits then that would be a much bigger problem by itself. Cellebrite would have no reason to execute or interpret anything off the target device in this stage. If they were doing that then the Signal article would of pointed that out first.

Re: Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer

#337

Earlier quoted context omitted.

Doesn't matter. When you can go through every message on someones phone back for years, I'm sure you can find something to put nearly anyone in prison for. No need to tell the court how you found out about the lawnmowing for the neighbour that was never reported to the IRS...

When you can call into question the data integrity of the items on the device and whether the information from that device is accurate or was inserted by the machine used to break into it, that is some very basic fourth amendment stuff that could possibly get all items taken from the device deemed inadmissible.

Parallel construction is still a possibility.

Not to mention regimes that don’t actually care about things like evidence being “legally admissible”.

Re: Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer

#338
post #316

Earlier quoted context omitted.

Really REALLY bad idea - this is one of law enforcement's larger pet gadgets and companies, so the GP would not only have a particularly enthusiastic mob coming after them, said mob's pitchforks would have automatic cannon launchers and EMPs and push-button-activated nunchucks and all kinds of other crazy things that aren't legal for standard-issue pitchforks. So if the database is fingerprintable to the GP specifica…

I think it's a fair guess that a security researcher like that knows how to post on hn without leaving their home address. It's not particularly difficult.

Unfortunately HN / Cloudflare / Google still block some Tor users with the privacy invasive software known as ReCAPTCHA. Not sure if they’ve switched to hcaptcha yet.

Re: Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer

#339
post #289

Earlier quoted context omitted.

They don't have to read that. The defense lawyers have to read it, and the people in law enforcement need to read the cases where judges throw out Cellebrite evidence based on that.

The worst enterprises using Cellebrite don't really have to worry about defense lawyers.

No, but Cellebrite does because their credibility is what sells their products to law enforcement. It wouldn't kill all their sales, but enough to be painful.

Re: Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer

#340
post #327

Earlier quoted context omitted.

Oooh of course! Thanks!

Also can be "the fine article" when used in a non-antagonistic way! I think it originated with "RTFM" which was an old unix admin way of saying read the fucking manual (or man page).

Yes RTFM I'm very familiar with, which is why I should've connected the two.
Post reply on HN