Earlier quoted context omitted.
Files will only be returned for accounts that have been active installs for some time already, and only probabilistically in low percentages based on phone number sharding. We have a few different versions of files that we think are aesthetically pleasing, and will iterate through those slowly over time. Pretty sure it's the former, since the above is a way to ensure that Cellebrite can't just gather all implied expl…
This indeed looks like a FUD statement, implying that they can have an infinite amount of potential vulnerabilities. Realistically though, writing parsers that do not yield control of your whole device is not that complex. The people exploiting iOS zero days can certainly do it.
Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer
61–70 of 352 posts
Re: Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer
#62This is pretty irksome. I get how satisfying it must feel, but the one thing I want as a Signal proponent is for the app to be boring and reliable. That means make it easy to use enough to be mainstream, squash bugs, and do all the lovely security work you do. That does not mean adding stuff like untraceable cryptocurrency payments or very publicly tweaking the noses of law enforcement, and bragging about how you're…
Signal has a strong ideology. If you don’t want to be a part of that then don’t use the app.
Re: Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer
#63As a Signal user and moxie fan I love that post, but I worry that it places Signal in legal peril from Apple. My fear, and prediction, is that the authorities will frame this as an even more egregious attack on law enforcement and that interfering with investigations is a crime (I'm not a lawyer, but I play one in hacker news comments, and that sounds like a crime). They'll lean on the app stores and the app stores w…
2. Signal stirred FUD in a blog post. That's a very different thing from actually doing it.
Re: Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer
#64Re: Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer
#65Re: Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer
#66Earlier quoted context omitted.
Signal isn't going to actually do it, they know how that would end, they're just playing the FUD game in the other direction. Which I am 100% on board with.
Maybe the one thing worse than boasting that you're putting malware in your product is boasting about it and not doing it.
Re: Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer
#67This is truly a hacker’s retort. It attacks Cellebrite's ability to operate by casting doubt on the reports generated by the product that their customers may wish to use in court. It places them in legal peril from Apple, and removes any cover Apple would have to not take legal action. (I assume someone at Apple knew they were shipping their DLLs?) It makes a thinly-veiled threat that any random Signal user's data ma…
Fortunately, parallel construction means you never really have to throw out bad evidence as long as you can find some good evidence too!
Re: Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer
#68Earlier quoted context omitted.
Not really. The same circumstances exist for almost all digital evidence. Of course, a lot of Cellebrite usage is extrajudicial already.
If you're failing some basic security it isn't going to give much confidence. But also users don't know now if their systems will explode if they try to gather Signal (or other app) data.
Re: Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer
#69i find it remarkably unbelievable someone would put a cellebrite bag in the back of a truck given the price alone.. and the timing too. sure