Live data from Hacker News

Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer

signal.org

71–80 of 352 posts

Re: Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer

#71
post #11

They literally said the unit fell off a truck. Funny... Correctly me if I am wrong, but did they really say they were going to be doing active attacks against Cellebrite units? Also funny... but they probably are not actually going to be doing that.

They didn't actually say anything of the sort. They may have implied some stuff. Anything they did imply wouldn't be an active attack though, it would be a passive one, triggered only if Cellebrite tried to gather data from the Signal app on phones. Not gathering info from a phone, or not gathering Signal data from a phone, would both be ways Cellebrite could avoid this potential passive attack.

I read nothing about an attack of any method or type at all.

If Cellebrite decides to punch a spiky rock they could have just not done that in the first place.

Re: Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer

#72
post #7

This is truly a hacker’s retort. It attacks Cellebrite's ability to operate by casting doubt on the reports generated by the product that their customers may wish to use in court. It places them in legal peril from Apple, and removes any cover Apple would have to not take legal action. (I assume someone at Apple knew they were shipping their DLLs?) It makes a thinly-veiled threat that any random Signal user's data ma…

Cellebrite acquired BlackBag Technologies recently. BlackBag emerged from Apple's security team.

Re: Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer

#74

As a Signal user and moxie fan I love that post, but I worry that it places Signal in legal peril from Apple. My fear, and prediction, is that the authorities will frame this as an even more egregious attack on law enforcement and that interfering with investigations is a crime (I'm not a lawyer, but I play one in hacker news comments, and that sounds like a crime). They'll lean on the app stores and the app stores w…

1. Any app could do it. 2. Signal stirred FUD in a blog post. That's a very different thing from actually doing it.

Well, if you read the whole blog post, it certainly seems like they're actually doing it.

Re: Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer

#75
post #68

Earlier quoted context omitted.

If you're failing some basic security it isn't going to give much confidence. But also users don't know now if their systems will explode if they try to gather Signal (or other app) data.

The quality of forensics software is extremely low; a similar story was once written about EnCase, and had zero impact on any legal case anywhere.

https://insights.sei.cmu.edu/blog/forensics-software-and-ora... ?

Re: Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer

#76
post #72
post #7

This is truly a hacker’s retort. It attacks Cellebrite's ability to operate by casting doubt on the reports generated by the product that their customers may wish to use in court. It places them in legal peril from Apple, and removes any cover Apple would have to not take legal action. (I assume someone at Apple knew they were shipping their DLLs?) It makes a thinly-veiled threat that any random Signal user's data ma…

Cellebrite acquired BlackBag Technologies recently. BlackBag emerged from Apple's security team.

Fitting name.

Black-bag the opposition politican, and then black-bag her phone.

Re: Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer

#77
post #64

A reminder that you can pair lock your iPhone to prevent analysis by Cellebrite or similar tools: https://arkadiyt.com/2019/10/07/pair-locking-your-iphone-wit...

Do we (reasonably) know if this still works?

There was a vulnerability in this technique that was fixed in iOS 11: https://labs.f-secure.com/advisories/apple-ios-host-pairing-.... If someone found another vulnerability and shared it with Cellebrite, then it doesn't work. If they haven't, then it still does.

Re: Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer

#78
post #6

So I wonder, why disclose this? This will just prompt Cellebrite to improve its security process and sandbox the entire tool. If they wanted to destroy the credibility of the tool, using the vulnerabilities to silently tamper with the collected data or even leaking it online would be a much better option and hit them without any warning, not only jeopardizing those cases but forever casting doubt on not just Cellebri…

For one thing, it could otherwise waste a lot of time for the poor white hat hacker who tries to figure out why this oddly formatted file suddenly exists in the app data.

And it doesn't destroy the credibility of the tool to silently mess with its data. People have to know it's happening.

Re: Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer

#79
If it's true that you can grab a Cellebrite hardware piece without too much difficulty (Ebay, etc - and note I'm not speaking from expertise so someone please fact check me), I'd find it hard to believe Apple wouldn't have done this kind of inspection themselves and/or noticed those DLLs being shipped.

Curious if there'll be a response of sorts.

Re: Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer

#80
post #11

Earlier quoted context omitted.

They didn't actually say anything of the sort. They may have implied some stuff. Anything they did imply wouldn't be an active attack though, it would be a passive one, triggered only if Cellebrite tried to gather data from the Signal app on phones. Not gathering info from a phone, or not gathering Signal data from a phone, would both be ways Cellebrite could avoid this potential passive attack.

The digital equivalent of "stop hitting yourself". Notwithstanding their crypto issue, this gives me renewed confidence in Signal's team.

To me it seems more like the equivalent of leaving booby trapped packages to be found by porch pirates. Or putting laxatives (or worse) in your sandwich to get back at the unknown coworker stealing your lunch. Both of which are considered illegal in the US.

Assuming these files actually contain exploits. Maybe they do maybe they don't. You feeling lucky Cellebrite?

Post reply on HN