Live data from Hacker News

Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer

signal.org

91–100 of 352 posts

Re: Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer

#91
I don't understand the seeming incongruity between these two statements:

On the one hand:

> One way to think about Cellebrite’s products is that if someone is physically holding your unlocked device in their hands, they could open whatever apps they would like and take screenshots of everything in them to save and go over later. Cellebrite essentially automates that process for someone holding your device in their hands.

But on the other hand:

> We are of course willing to responsibly disclose the specific vulnerabilities we know about to Cellebrite if they do the same for all the vulnerabilities they use in their physical extraction and other services to their respective vendors, now and in the future.

If UFED just copies data from unlocked phones, why would they be using vulnerabilities to do so?

I guess my question is, is Cellebrite capable of copying locked devices, or more to the point - has vulnerabilities to unlock devices without knowing the access PIN?

Re: Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer

#92

This is pretty irksome. I get how satisfying it must feel, but the one thing I want as a Signal proponent is for the app to be boring and reliable. That means make it easy to use enough to be mainstream, squash bugs, and do all the lovely security work you do. That does not mean adding stuff like untraceable cryptocurrency payments or very publicly tweaking the noses of law enforcement, and bragging about how you're…

The problem with being boring while attacking powerful institutions (like LEOs or nation states) is that it only works as long as you're small enough to stay below their radar. After a certain point, the material reality will sink in that you're a threat, and they're going to take action against you regardless of how you carry yourself. It's totally possible, given that we're starting to hear more and more accounts of powerful people using Signal, that we're approaching that tipping point, and a more gloves-off approach might be necessary.

That being said, I agree with you 100% on the cryptocurrency payments issue and think that was a misstep on their part.

Re: Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer

#93

Earlier quoted context omitted.

Signal isn't going to actually do it, they know how that would end, they're just playing the FUD game in the other direction. Which I am 100% on board with.

Maybe the one thing worse than boasting that you're putting malware in your product is boasting about it and not doing it.

Is it malware if users desire for their devices to be resistant to surveillance tools?

Re: Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer

#94

i find it remarkably unbelievable someone would put a cellebrite bag in the back of a truck given the price alone.. and the timing too. sure

"fell off the back of a truck" is an idiom [1]. It's not meant literally. [1] https://www.phrases.org.uk/meanings/fell-off-the-back-of-a-t...

they actually put it a photo of it on the street too

Re: Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer

#95
post #7

This is truly a hacker’s retort. It attacks Cellebrite's ability to operate by casting doubt on the reports generated by the product that their customers may wish to use in court. It places them in legal peril from Apple, and removes any cover Apple would have to not take legal action. (I assume someone at Apple knew they were shipping their DLLs?) It makes a thinly-veiled threat that any random Signal user's data ma…

All that trouble becaused a bag conveniently "fell from a truck". All in all I'm really happy for all this.

Yup. Those things have way to "fell from a truck". Another win for the "fell from a truck" gang ;)

Re: Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer

#96

I don't understand the seeming incongruity between these two statements: On the one hand: > One way to think about Cellebrite’s products is that if someone is physically holding your unlocked device in their hands, they could open whatever apps they would like and take screenshots of everything in them to save and go over later. Cellebrite essentially automates that process for someone holding your device in their ha…

Based on the post, it sounds like there's some data parsing going on (possibly to present the data in a user-friendly way?), and the parsing step uses outdated versions of software (such as ffmpeg) which have well-documented vulnerabilities in them.

Re: Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer

#97

I don't understand the seeming incongruity between these two statements: On the one hand: > One way to think about Cellebrite’s products is that if someone is physically holding your unlocked device in their hands, they could open whatever apps they would like and take screenshots of everything in them to save and go over later. Cellebrite essentially automates that process for someone holding your device in their ha…

Cellebrite claims,

"Lawfully access locked devices with ease Bypass pattern, password or PIN locks and overcome encryption challenges quickly on popular Android and iOS devices"

https://www.cellebrite.com/en/ufed/

Re: Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer

#98
post #74

Earlier quoted context omitted.

1. Any app could do it. 2. Signal stirred FUD in a blog post. That's a very different thing from actually doing it.

Well, if you read the whole blog post, it certainly seems like they're actually doing it.

Nah. The cost/benefit of saber rattling makes tons of sense while the cost/benefit of actually doing it makes much less sense. Probably.

No amount of certainty about Marlinspike's actions should comfort Cellebrite, though, because Moxie Marlinspike isn't the only person allowed on the app store.

Re: Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer

#99
post #6

So I wonder, why disclose this? This will just prompt Cellebrite to improve its security process and sandbox the entire tool. If they wanted to destroy the credibility of the tool, using the vulnerabilities to silently tamper with the collected data or even leaking it online would be a much better option and hit them without any warning, not only jeopardizing those cases but forever casting doubt on not just Cellebri…

Any court case where Cellebrite's tools have been used are now in jeopardy since the defence can just say that they were hacked by someone else. There's now reasonable doubt that Cellebrite can't be trusted. This damages their reputation with governments too.

This is unlikely to be the case, despite the vulnerabilities that are described.

The process of e-discovery is rife with risks of this sort. When you forensically collect data from a random set of devices from a party that may or may not have porn, HIPAA, GDPR, sample viruses, malware, who know what all.

The short version of it even if the inhaling of this data crashes the device, there are mitigations and protections that will allow the evidence to be ultimately produced.

A crash of the windows host in collection will not invalidate the case.

disclosure: ex-CSO of Relativity, leading provider of e-discovery software.

Re: Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer

#100

Earlier quoted context omitted.

Indeed, how convenient . If it truly did fall off the truck right while he is on a walk then there is the possibility that is a rubber duckie attack. This is basically the equivalent of leaving a USB flash drive lying around. I hope the author took the necessary precautions when reverse engineering the device. Companies like cellebrite have deep connections to certain three letter communities that staging this sort o…

"falling off a truck" is slang for "was stolen".

Given the sort of business Cellebrite is in, they would probably still want to treat anything connected to it with an overabundance of caution.
Post reply on HN