Live data from Hacker News

Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer

signal.org

341–350 of 352 posts

Re: Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer

#341
Crossing the streams, the US Postal Inspectors Service (which hosts iCOP, detailed in a recent Yahoo story) are a Cellebrite customer:

https://www.uspis.gov/wp-content/uploads/2020/02/FY-2019-ann... (p. 35)

See: https://news.ycombinator.com/item?id=26892180 https://news.yahoo.com/the-postal-service-is-running-a-runni...

Re: Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer

#342
post #290

Earlier quoted context omitted.

The question of whether damaging reports would be illegal is separate from whether booby traps are illegal. And they're not, in the broad case: Booby trapped packages are only illegal if they cause bodily harm or damage or are negligent along those lines.

The actual crime would be different; the former would be assault, while the latter would be unauthorized access under the CFAA, but I think the principle applies to both. In both cases the intent to cause harm exists, and doesn't become irrelevant just because the victim had to put themselves in a situation to trigger that harm. If anything I think there is a stronger case against leaving exploits around where softwa…

Ahhh... Au contraire. The Cellebrite exploits a device for root. Technically that is sidestepping most permissions frameworks as a matter of expediency, but I assure you scanning things and being able to access them by default is not a given. Access Controls are digital fiefdoms unto the implementer's design, and if it is so that a scan should be responded to with a malicious payload, it is not at all anything more than a quirk of the configuration of that device.

If you want to start trying to project human legality into the computing world, you're going to have a really, really bad time. Human legal logic and digital logic do not at all mix.

Things get even hairier with things like a hard disk full of a nation state's classified info, where a root terminal has been left open.

The computer will not argue a lick about producing those contents, but I assure you, someone else will most vigorously object.

And by CFAA, and everything else under the sun, Law Enforcement wants extra-priviliged access reserved for themselves which no inherent property of digital logic or programming need guarantee.

Practically implementing such programs/filesystems/systems-as-a-whole is an exercise left to the reader. As is the consequences of doing so in a particularly authoritarian leaning society at the moment.

Re: Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer

#343
post #290

Earlier quoted context omitted.

The actual crime would be different; the former would be assault, while the latter would be unauthorized access under the CFAA, but I think the principle applies to both. In both cases the intent to cause harm exists, and doesn't become irrelevant just because the victim had to put themselves in a situation to trigger that harm. If anything I think there is a stronger case against leaving exploits around where softwa…

Ahhh... Au contraire. The Cellebrite exploits a device for root. Technically that is sidestepping most permissions frameworks as a matter of expediency, but I assure you scanning things and being able to access them by default is not a given. Access Controls are digital fiefdoms unto the implementer's design, and if it is so that a scan should be responded to with a malicious payload, it is not at all anything more t…

[deleted]

Re: Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer

#344
post #290

Earlier quoted context omitted.

The actual crime would be different; the former would be assault, while the latter would be unauthorized access under the CFAA, but I think the principle applies to both. In both cases the intent to cause harm exists, and doesn't become irrelevant just because the victim had to put themselves in a situation to trigger that harm. If anything I think there is a stronger case against leaving exploits around where softwa…

Ahhh... Au contraire. The Cellebrite exploits a device for root. Technically that is sidestepping most permissions frameworks as a matter of expediency, but I assure you scanning things and being able to access them by default is not a given. Access Controls are digital fiefdoms unto the implementer's design, and if it is so that a scan should be responded to with a malicious payload, it is not at all anything more t…

[deleted]

Re: Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer

#345
post #289

Earlier quoted context omitted.

The worst enterprises using Cellebrite don't really have to worry about defense lawyers.

No, but Cellebrite does because their credibility is what sells their products to law enforcement. It wouldn't kill all their sales, but enough to be painful.

If you, as I do, hold that personal devices should be private, then you're probably happy with the extraction tools being weak. Let them remain complacent.

Re: Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer

#346

How do Cellebrite maintain "Chain of custody"? If they need to modify (hack) the device to get access. I was of the understanding, that if any file is modified then "chain of custody" is no longer in good standing, and therefore cannot be used as evidence.

You wish. All they need to do is track which files they modify and not touch the other ones. I doubt it would be fruitful to explore that angle in court

Re: Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer

#347
post #51
post #6

So I wonder, why disclose this? This will just prompt Cellebrite to improve its security process and sandbox the entire tool. If they wanted to destroy the credibility of the tool, using the vulnerabilities to silently tamper with the collected data or even leaking it online would be a much better option and hit them without any warning, not only jeopardizing those cases but forever casting doubt on not just Cellebri…

Whether Cellebrite is secure or not has really not much impact on Signal. Shore up Cellebrite's security, don't, either way, pretty much same threat to users. But calling them out like this could force them to placate their customers by spending money on software security --- something they apparently haven't been doing --- and inflicting costs on your adversary is good praxis.

I bet Sun Tzu would also extol the value of allowing your weekend to remain complacent. This disclosure may make them harden up.

Re: Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer

#348
post #346

How do Cellebrite maintain "Chain of custody"? If they need to modify (hack) the device to get access. I was of the understanding, that if any file is modified then "chain of custody" is no longer in good standing, and therefore cannot be used as evidence.

You wish. All they need to do is track which files they modify and not touch the other ones. I doubt it would be fruitful to explore that angle in court

I attended a conference back in the early 00's, where a member of GHCQ presented. He spoke about assisting on 911, obtaining forensic evidence from hard drives and the lengths that his team had to go to, to make sure that no files where changed while creating a clone of the drives. He stated that they can not just turn on a computer when they have seized it, as there would be about 800 files altered before Windows had even booted to the login screen. This, he stated, would destroy the chain of evidence. He might have been full of shit though.

Re: Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer

#349
post #298

Earlier quoted context omitted.

I am happy to see the bag survived its most untimely truck tumble while remaining a e s t h e t i c a l l y - - - p l e a s i n g.

What a sturdy bag it is!

I love Kim Zetter's tweet:

Must have been a turnip truck https://twitter.com/KimZetter/status/1384936715769503745

That's a dig at the turnipesque savvy of Cellebrite, which royally stumbled into this.

cf. https://www.dwt.com/blogs/privacy--security-law-blog/2015/03... > FCC chair Wheeler said the FCC “didn’t just fall off the turnip truck.” Through CALEA, CPNI, and CSRIC, Wheeler said the agency has been working to protect consumer privacy.

Re: Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer

#350

Earlier quoted context omitted.

It's kind've hard to argue about having random unknown data laying around, but... The insinuation that my device may be host to something potentially malicious is concerning. It gets a little worse that it can change, without notice. I'd tend to trust Signal and their security, but the potential for that mechanism to be hijacked is always present. They've certainly made it hard, though, and I think the folks at Signa…

Everyone can inspect the Signal app's source code, though, and make sure that nothing funny is happening with the "aesthetically pleasing" files it downloads.

If they publish the aesthetically pleasing file source code doesn't that defeat the point?
Post reply on HN