Live data from Hacker News

Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer

signal.org

1–10 of 352 posts

Re: Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer

#3
> In completely unrelated news, upcoming versions of Signal will be periodically fetching files to place in app storage. These files are never used for anything inside Signal and never interact with Signal software or data, but they look nice, and aesthetics are important in software.

I wish I could see those files in action...

Re: Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer

#4

> In completely unrelated news, upcoming versions of Signal will be periodically fetching files to place in app storage. These files are never used for anything inside Signal and never interact with Signal software or data, but they look nice, and aesthetics are important in software. I wish I could see those files in action...

I wonder if the intention here is to deter Cellebrite from parsing Signal files? Or to pressure them into fixing their security vulnerabilities?

Re: Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer

#5
post #4

> In completely unrelated news, upcoming versions of Signal will be periodically fetching files to place in app storage. These files are never used for anything inside Signal and never interact with Signal software or data, but they look nice, and aesthetics are important in software. I wish I could see those files in action...

I wonder if the intention here is to deter Cellebrite from parsing Signal files? Or to pressure them into fixing their security vulnerabilities?

or just flipping them off, which seems OK too.

Re: Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer

#6
So I wonder, why disclose this?

This will just prompt Cellebrite to improve its security process and sandbox the entire tool.

If they wanted to destroy the credibility of the tool, using the vulnerabilities to silently tamper with the collected data or even leaking it online would be a much better option and hit them without any warning, not only jeopardizing those cases but forever casting doubt on not just Cellebrite but their competitor tools.

Re: Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer

#7
This is truly a hacker’s retort.

It attacks Cellebrite's ability to operate by casting doubt on the reports generated by the product that their customers may wish to use in court.

It places them in legal peril from Apple, and removes any cover Apple would have to not take legal action. (I assume someone at Apple knew they were shipping their DLLs?)

It makes a thinly-veiled threat that any random Signal user's data may actively attempt to exploit their software in the future and demonstrates that it's trivial to do so.

edited to add a bonus one:

Publish some data about what they are doing to help create a roadmap for any other app that doesn't want their data to be scanned.

Re: Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer

#8
They literally said the unit fell off a truck. Funny...

Correctly me if I am wrong, but did they really say they were going to be doing active attacks against Cellebrite units? Also funny... but they probably are not actually going to be doing that.

Re: Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer

#10
post #6

So I wonder, why disclose this? This will just prompt Cellebrite to improve its security process and sandbox the entire tool. If they wanted to destroy the credibility of the tool, using the vulnerabilities to silently tamper with the collected data or even leaking it online would be a much better option and hit them without any warning, not only jeopardizing those cases but forever casting doubt on not just Cellebri…

Any court case where Cellebrite's tools have been used are now in jeopardy since the defence can just say that they were hacked by someone else. There's now reasonable doubt that Cellebrite can't be trusted. This damages their reputation with governments too.
Post reply on HN