If it's true that you can grab a Cellebrite hardware piece without too much difficulty (Ebay, etc - and note I'm not speaking from expertise so someone please fact check me), I'd find it hard to believe Apple wouldn't have done this kind of inspection themselves and/or noticed those DLLs being shipped. Curious if there'll be a response of sorts.
Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer
81–90 of 352 posts
Re: Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer
#82A reminder that you can pair lock your iPhone to prevent analysis by Cellebrite or similar tools: https://arkadiyt.com/2019/10/07/pair-locking-your-iphone-wit...
Do we (reasonably) know if this still works?
Re: Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer
#83> One way to think about Cellebrite’s products is that if someone is physically holding your unlocked device in their hands, they could open whatever apps they would like and take screenshots of everything in them to save and go over later. Cellebrite essentially automates that process for someone holding your device in their hands. Aren't Cellebrite products/services more advanced than that? I mean don't they use pu…
Re: Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer
#84> One way to think about Cellebrite’s products is that if someone is physically holding your unlocked device in their hands, they could open whatever apps they would like and take screenshots of everything in them to save and go over later. Cellebrite essentially automates that process for someone holding your device in their hands. Aren't Cellebrite products/services more advanced than that? I mean don't they use pu…
Re: Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer
#85Earlier quoted context omitted.
Indeed, how convenient . If it truly did fall off the truck right while he is on a walk then there is the possibility that is a rubber duckie attack. This is basically the equivalent of leaving a USB flash drive lying around. I hope the author took the necessary precautions when reverse engineering the device. Companies like cellebrite have deep connections to certain three letter communities that staging this sort o…
> If it truly did fall of the truck lol
Re: Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer
#86Earlier quoted context omitted.
Do we (reasonably) know if this still works?
This still works as written. Just test it yourself with a Mac and Apple Configurator.
Re: Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer
#87Earlier quoted context omitted.
I think they mention Apple in an attempt to force them to defend their copyright, else they risk losing it. I assume Apple will choose to file for copyright infringement than risk being accused of collusion and lose the copyright on that iTunes or parts of it.
That's not how copyrights work, you're confusing it with trademarks.
Not clear which the parent was talking about. Maybe both?
Re: Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer
#88Earlier quoted context omitted.
All that trouble becaused a bag conveniently "fell from a truck". All in all I'm really happy for all this.
Indeed, how convenient . If it truly did fall off the truck right while he is on a walk then there is the possibility that is a rubber duckie attack. This is basically the equivalent of leaving a USB flash drive lying around. I hope the author took the necessary precautions when reverse engineering the device. Companies like cellebrite have deep connections to certain three letter communities that staging this sort o…
Re: Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer
#89Earlier quoted context omitted.
You wouldn't imply that Signal had framed you. You would imply that someone else had framed you using the same vulnerabilities as Signal has now indicated exists. i.e. You can't trust Cellebrite because it's now known to be trivial to subvert their software. It's also difficult for Cellebrite to prove that there aren't remaining vulnerabilities in their software since Signal didn't disclose the problems they found an…
You can't just claim an unknown entity framed you and hope to get anywhere. Heck, you could just as well claim that Cellebrite themselves had it in for you. Cellebrite has never claimed any particular exploits in Signal. Signal is exploitable in this particular way for entirely obvious and common reasons.
In computer forensics it's ALL about being able to verify, without a shadow of doubt that something is what they say it is. Chain of custody rules everything. This blasts a huge gaping hole in all that. He's proven that chain of custody can be tampered with and undetected. Files can be planted, altered or erased. Reports can altered. Timestamps can be changed. The host OS can be exploited. It calls all past and future cellbrite reports into question. Cellbrite can no longer guaranty their software acts in a consistent reliable verifiable way. It leaves doubt.
Re: Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer
#90This is truly a hacker’s retort. It attacks Cellebrite's ability to operate by casting doubt on the reports generated by the product that their customers may wish to use in court. It places them in legal peril from Apple, and removes any cover Apple would have to not take legal action. (I assume someone at Apple knew they were shipping their DLLs?) It makes a thinly-veiled threat that any random Signal user's data ma…
> It attacks Cellebrite's ability to operate by casting doubt on the reports generated by the product that their customers may wish to use in court. Fortunately, parallel construction means you never really have to throw out bad evidence as long as you can find some good evidence too!
It reminds me of the story of https://en.wikipedia.org/wiki/Annie_Dookhan