11 ms·
Israeli firm can steal phone data in seconds
- turc1656 10y ago"But privacy and rights activists worry such powerful technology can wind up in the wrong hands, leading to abuses." Am I to believe that this firm is the right hands? Or government? Please...all hands are the wrong hands. These vulnerabilities need to be closed. I wouldn't be surprised if the NSA or some other government tentacle was paying them not to make whatever they found known. Gee, I sound paranoid. What am I thinking, our government would never do that. Oh wait... http://www.reuters.com/article/us-usa-security-rsa-idUSBRE9BJ1C220131220 http://www.reuters.com/article/us-usa-security-rsa-idUSBRE9B...
- flipp3r 10y agoActually Cellebrite themselves have been victim of some kind of hack last month and had a load of their internal documents leaked online. So no, if any, this firm is _not_ the right hands.
- rdtsc 10y agoAny place which hoards 0-days is a prime target. Even if they are considered to be the "right hands", the "wrong hands" could grab those exploits eventually.
- AtheistOfFail 10y agoWhen the target holds a lot of $1 million dollar 0-day exploits, the target is worth hacking into.
- sjwright 10y agoThe only "right hands" for a 0-day exploit is the device manufacturer.
- benchaney 10y agoAnd even then, only some manufacturers.
- user5994461 10y ago> I wouldn't be surprised if the NSA or some other government tentacle was paying them not to make whatever they found known. It looks like your are unsure, so let me clarify. There really are companies whose only business is to find and sell vulnerabilities to states. (Whether it's exclusive is just a matter of negotiations).
- superflyguy 10y agoMost US "charity" ends up in Israel too. Best to think of them as if they were an entirely US-funded university you then have to pay to use the services of.
- wahsd 10y agoYou highlight a kind of social disconnect among a segment of the population that are kind of eternal liberal optimist loyalists that have no problem trusting their parent, the government with any and all sorts of individual rights. It is precisely why some people simply cannot look through or past the notion that the government could somehow not be a benevolent parent that only has our best interest in mind and are thereby more than willing to cede all sorts of responsibilities and rights. It is the frame of mind behind many different dualistic issues like gun rights, state's rights vs strong central power consolidation, immigration, education, etc.
- Steko 10y agoPeople don't favor gun control because they're eternal optimists about the government's benevolence, that is a ridiculous straw man. Generally people favor gun control because -- to use the same language -- they are not eternal optimists about the benevolence of their fellow citizens who sometimes murder large groups of innocents.
- CamperBob2 10y agoIf they bothered to crack a history book, of course, they'd come to understand that on a long-enough timeline, they're most likely to be shot by their own government, military, or police forces. But of course, That Can't Happen Here, because We're Special. (How many times have you heard that schtick lately?) After that, the person most likely to shoot you is a fellow criminal that you're either associated with or competing with, such as a rival gang member. Then comes suicide and firearm-related accidents. Everything else is just so much statistical noise. Meanwhile, the American left's inexplicable insistence on gun control as a key platform element continues to cost them elections they otherwise could have won handily.
- andrepd 10y agoI don't even know where to start. Do you have any sources on your first claim? Or on your other claims? Also, gun control costs elections that would otherwise be won handily? With so much going on on this last election, do you think the barely discussed topic of gun control was the single most important topic to blame for an election that could otherwise have been won, and won handily? Would you have Hillary be against gun control, offering the majority of people that favour it no major candidate reflecting their beliefs?
- wyldfire 10y ago> Among the data the firm claims to be able to access are text messages deleted years previously. Among all the claims this one seems like it might be one that holds up with very recent iOS/Android releases. It would be interesting to find out whether they rely solely on the encryption to protect the deleted messages and whether overwriting the data would be thwarted by flash device wear-leveling indirection.
- bobbob1 10y agoCache is not cleaned if the cellphone is on, a reboot would suffice that in most Android. Blackberry is different and I don't know iOS enough to tell, but they do integrate with iCloud.
- 45h34jh53k4j 10y agoIt will be interesting if Apple went after Cellebrite under the DMCA anti-circumvention clauses. I would laugh if their product became illegal in the United States.
- tdkl 10y agoProbably not, it's an Israeli firm.
- otaviokz 10y agoPretty much my reasoning too.
- r00fus 10y agoAny sales to US firms could be curtailed or punished. Just like security itself - the goal is to provide enough barriers so predators go looking elsewhere for easier prey.
- mschuster91 10y ago> Any sales to US firms could be curtailed or punished. That doesn't really restrict the NSA, CIA, FBI or any other agency/PD from buying their services. After all, that's what "black budgets" are for.
- r00fus 10y agoMost of these firms use private contractors to do the dirty work. Unless contractors can bypass legal oversight, they'll be constrained as well.
- Daishiman 10y agoOverseas contractor hired by a shell corporation gets the phone sent outside of the US. Boom. All this assuming they even care about legal compliance, which I am sure that under the correct circumstances it won't matter one bit.
- 45h34jh53k4j 10y agoSo we have learned that some phone vendors give Cellebrite their phones before they reach market in order for them to discover and exploit vulnerabilities. Apple refuses to do business with these 'forensic' criminals. Do not purchase a phone from a vendor that engages in this unethical practise.
- ikonst 10y agoCellebrite got its start with the UME, a phone memory transfer tool for carriers' (POS and support). Carrier-oriented tools are a major part of its operations, though there have been some talks about spinning this off to a separate company. Cellebrite gets early access to phones NOT due to its forensics operations, but for UME, since carriers (and that's lots(!) of carriers worldwide) are very much interested in good consumer experience on the devices' launch day. I actually doubt it's been particularly significant to its forensics operations.
- module0000 10y agoIt goes without saying - don't make this easy for them(or anyone). Use a strong alphanumeric password on your mobile devices. It's annoying and inconvenient until it saves your ass - there is still no "fast" way to crack a password like "My 42nd spaceship had 4 hearts of gold.", but it's not that difficult for your brain to remember. Fingerprint unlock can save you some of the PITA of typing it - just be sure you power off your device when you have even the slightest chance of encountering an actor that could seize your mobile device - that way the passphrase will be required.
- drvdevd 10y agoAnother interesting point they mention is "recovering years long deleted texts." Consider the filesystem your phone uses for volumes it's writing data to and how it (probably just) unlinks files when deleted... [edit] and I should add a 'factory reset' will probably just write a new filesystem table over the old on disk without wiping anything on most devices
- jdironman 10y agoWhat about doing a factory reset, then use the 'encrypt device' option, then doing another factory reset. Would that provide an extra measure? Unless, of course, the data in it's final state before the final factory reset is un-encrypted.
- drvdevd 10y agoOf course it depends on the phone. Many qualcomm based Android devices seem to have had their Full Disk Encryption scheme broken at the moment [1], for example. But either way, if your disk encryption scheme doesn't fully wipe the disk before use, then any data that ever hit the disk unencrypted could still possibly be sitting there until its physical blocks are consumed (or could be in a cache somewhere). Again this also depends on the hardware, in this case the storage hardware itself. SSDs using TRIM can wipe unused, unencrypted blocks for example in some scenarios. Who knows about the particular functioning of some SD type controller in a phone or even the card's own embedded OS [2]. I would say if you have data on your smartphone you don't want recoverable at rest, take module0000's advice, then also use encryption, and then also use a multi-pass wipe tool on particluar files. Of course all of this could still not work. For example, I'm not sure what the forensic ramifications of a seemingly more complex filesystem like APFS will be in the near future when it hits iOS. [1] https://bits-please.blogspot.com/2016/06/extracting-qualcomms-keymaster-keys.html https://bits-please.blogspot.com/2016/06/extracting-qualcomm... [2] https://www.bunniestudios.com/blog/?p=3554 https://www.bunniestudios.com/blog/?p=3554
- 1024core 10y ago"Could you do anything to deprive them from throwing a stone at someone or from driving a car and running over people? "You can't blame the car manufacturer at that point for delivering a car that was utilised to commit that kind of crime," he said. This is specious reasoning. The point of a car is not to run over people; it's to go from point A to point B. This technology, on the other hand, has only one purpose: to break into cellphones.
- libeclipse 10y agoA classic example of attacking the straw man.
- ucaetano 10y ago"Ben-Peretz said the company vets clients and always respects local laws, but the governments are primarily responsible." Just following orders and the local laws...
- dalbasal 10y agoI think you're misunderstanding that quote. He's saying (if I understand correctly, it's awkwardly phrased) that his company sells only to a small number of clients who are all regimes (meaning states). There are only a handful so he can vet them and demand commitments that the technology will only be used for good. Plenty of other reasons to disagree. But, he is basically agreeing with you that this technology should be treated as a dangerous weapons-like thing and controlled in the way the sale of advanced weapons is controlled.
- verbify 10y agoThere can be good reasons to break into cellphones, just like there can be good reasons to have a lock pick. Our problems stem from overfunded and underregulated intelligence agencies, not from the tools they use.
- gnarbarian 10y agoI think it's an important distinction. The crime is in how it's used, not in the technology itself. Banning the tech outright only affects actors who are willing to follow the law. So banning this tool would mostly limit white hats. The same principle applies to gun rights for example. The gun itself isn't the problem, it's how someone chooses to use it. (self defense vs crime). Nobody is an absolutist here, everyone draws the line somewhere slightly different. Outlawing the tech ensures that good guys lose the arms race every time. When I say good guys I don't necessarily mean the government. I mean anyone out there who is not using the tech for malicious intent. People using guns for self defense, breaking into an encrypted device to solve a crime, or retrieve lost work etc. This keeps the focus on improving the actual technology (encryption). Rather than just banning law abiding citizens from taking part.
- alimbada 10y agoThey [the government] ask people to login to their email accounts and unlock their phones at the border. They really don't even need any technology to steal data. Intimidation works for them already.
- brianwawok 10y agoThen we just need a phone inside a phone right? Provide them with a fake password that shows no data, has 1 kids game app, and gives you plausible deniability. If coded correctly would be no way to prove if there is or is not a second deeper encrypted device.
- wang_li 10y agoBackup your phone. Wipe your phone. Cross the border. Restore your phone.
- alimbada 10y agoOr don't take your phone. On the other hand they've asked people to login to their email accounts using laptops they've provided.
- PhantomGremlin 10y agoSame thing for your laptop. Back everything up to the cloud, then load a clean copy of the OS before crossing the border.
- SG- 10y agoConfused why they didn't demo it breaking a modern iPhone instead of a random Android device.
- deutronium 10y agoRegarding the iPhone 5c, the attack from Sergei Skorobogatov is very interesting. "The bumpy road towards iPhone 5c NAND mirroring" - https://arxiv.org/abs/1609.04327 https://arxiv.org/abs/1609.04327 And the video: https://www.youtube.com/watch?v=tM66GWrwbsY https://www.youtube.com/watch?v=tM66GWrwbsY
- libeclipse 10y agoI wonder if they can crack devices that haven't been booted. Many of the newer smartphones encrypt data and require a password on boot.
- cxseven 10y agoToo bad Google made the boot password the same as the screen unlock password. Since virtually everyone wants to be able to quickly unlock their phone, this makes security a Hobson's choice.
- libeclipse 10y agoYeah I can see that being the case for the vast majority of users. Also it's a damned shame that Google enforces a limit of 16 characters for the password. My own password is a random 16 character string.
- ThatGeoGuy 10y agoFortunately the community has addressed both these claims, although you need root to set it up (you can remove after). An app on F-droid known as "Cryptfs Password" can change the encryption password separately from your screen unlock password. It also bypasses the 16 character limit, as the encryption key I used on my last phone was 27 characters. At the end of the day Android encryption runs using dm-crypt, so the same sort of rules apply. The 16 character limit is a UI limitation, and there's no technical reason for it. * Note: I fully acknowledge that Google needs to do better here, as I would never assume a normal user could root + install Cryptfs password + unroot after, but at least for those of us who can, we can do something in the meantime.
- golergka 10y agoWell otherwise the user will most likely forget the separate boot password as phones typically get rebooted once a month or so.
- cxseven 10y ago
- sqeaky 10y agoDoes encryption defeat this? If not how are they getting the key from memory? Does encryption defeat this when the device is off? If not what flaws exist in the encryption schemes?
- zw123456 10y agoI was wondering the same thing. If the data on the flash ram chip is not encrypted then worse case you just de-solder it and connect it to another computer and dump the data, I think I have seen that demonstrated someplace before. But I guess if they are using the users password you can just password cracking.
- ronreiter 10y agoEncryption could help but eventually exploits can beat anything.
- sqeaky 10y agoExploits are just ways to leverage those flaws. We have systems with no flaws for some older tech. Eventually we will fix this one too.
- amelius 10y agoSounds like a risky business to be in. If Apple decides to change their encryption technology, you could be out of business some time soon after a new release.
- chinathrow 10y agoOr you just buy the next 0day from your vendor of choice.
- anigbrowl 10y agoThere'll still be plenty of legacy users out there.
- chebastian 10y agoYour mistaken, looking at the forensic side of things burner phones are not your regular iphone or android. E.g random article from bestbuy. http://www.bestbuy.com/site/at-t-gophone-lg-b470-prepaid-cell-phone-black/5444000.p?skuId=5444000 http://www.bestbuy.com/site/at-t-gophone-lg-b470-prepaid-cel...
- Ftuuky 10y agoAren't they owned by a Japanese pachinko company?
- bobbob1 10y agoCellebrite was acquired by Sun but they're operating freely. Sun just wanted the IPO.
- ka4eli 10y agoSounds like an Apple advertisment.
- wahsd 10y agoThat's what I was basically thinking. Combine that with the recent mass malware discoveries on hundreds of millions of android phone, it really makes you wonder why anyone with any sensitivity regarding these issues buy anything but Apple. On the flip side, it's really a massively missed opportunity for Apple to not be paying guerrilla marketing types to push all the bad press about Android all over the place off the books.
- sjwright 10y agoAnd the good kind of advertising, because it's accurate. Apple did the hard engineering work across their entire software and hardware stack because they knew it was important. They didn't settle for good enough. They didn't weasel out of it by blaming "ease of use" concerns. They didn't argue that maximum security wasn't a high priority for their customers. They didn't deploy marketing slogans to pretend like they had done the hard engineering work. (cough Knox cough)
- r00fus 10y agoYou'd think if they could crack the latest iPhone/iOS they'd crow about it. The article seems to paint it as a "we're confident we could" - which seems bizarrely vague. Why would they do that when they claim they can crack an LG G4 wide open?
- JumpCrisscross 10y agoFrom the article: > Ben-Peretz remains confident his company can crack even the newest iPhones.
- eridius 10y agoThe next line in the article: > iOS devices have strong security mechanisms that give us a challenge, but if anyone can address this challenge and provide a solution to law enforcement, it is Cellebrite," he said, referring to Apple's operating system. This makes it sounds like Cellebrite actually cannot currently crack the latest phones running iOS 10, but the CEO is merely expressing his belief that they'll figure out how to do it. See how he's not saying "we can do it", but instead he's saying "if anyone can do it, it's going to be us".
- woobar 10y agoThis is a good point. But I am not sure they have demonstrated that they can crack a G4 wide open. They were able to access DCIM folder, which is very accessible by design. Even if they were able to bypass whatever protection this folder has ("password was disabled"), it is still far from wide open. They might be able to do what they claim, but not much was actually presented.
- JumpCrisscross 10y agoDoes anyone track the quantity of U.S. tax dollars which go to such firms?
- ronreiter 10y agoIt's a profitable company. It doesn't need US money. If your government needs to hack a phone that belongs to a terrorist to protect innocent US citizens then what's the problem? Oh, you're an antisemite. Sorry, missed that.
- JumpCrisscross 10y ago> Oh, you're an antisemite. Sorry, missed that. What? I'm opposed to using U.S. tax dollars to contravene the security of U.S.-designed, manufactured and used devices and operating systems. I don't care if it's the FBI [1], a Canadian company [2] or the Israelis. It's shitty that you devolve your rhetoric so quickly. This is the most disturbing exchange I've ever had on this forum. > If your government needs to hack a phone that belongs to a terrorist to protect innocent US citizens then what's the problem? Americans are innocent until proven guilty. If our government determines guilt without following due process, they (and those who aid and abet them) may be the ones acting illegally. [1] https://www.cnet.com/news/fbi-v-apple-we-dont-need-your-iphone-hack/ https://www.cnet.com/news/fbi-v-apple-we-dont-need-your-ipho... [2] http://www.cbc.ca/news/technology/blackberry-taps-user-messages-1.3620186 http://www.cbc.ca/news/technology/blackberry-taps-user-messa...
- ikonst 10y agoDoes anyone track? I guess as much anyone tracks any "U.S. tax dollars" going to any other US government stuff one doesn't like or agree with. (In other words, probably not much.) Cellebrite doesn't "target" the U.S. It happily develops forensic tools to target Chinese, U.S.-ian, heck, even Israeli phones (if there were any to speak of). Furthermore, Cellebrite don't sell exclusively to the U.S. They will sell to Canada, UK, France, Germany or any legit law enforcement agency that has budget. U.S. law enforcement may refrain from buying Cellebrite wares. They might decide to buy from a competitor, like Swedish firm MSAB. Heck, they may decide it's "unethical" to own such tools. While it might adversely affect Cellebrite's bottom line, I think it will first and foremost adversely affect U.S. police departments' capabilities.
- AWildDHHAppears 10y agoWhat exactly is wrong with a company buying a product on the retail market and figuring out how it works? I thought we were "hackers" here and want to assert our rights to "own" our equipment. At least we know that exploits may be available and we know not to put complete trust in our device security.
- Adverblessly 10y agoI wonder, if Ben-Peretz and his checks 250 researcher team can crack checks 150 phones a month what is stopping the <scary US government agency>/<Chinese equivalent>/<Russian equivalent> from forming a 2,500 researcher team and doing the same? It's not like there's a shortage of relevant skills in the US (supposedly responsible for stuxnet) or Russia. Or is it just that <scary government agency> doesn't want to share its toys with <local police>?
- mschuster91 10y agoAh well, with Mediatek based phones it's pretty easy - you can readback the whole storage once you have its partition map from a rooted device, or you know the size of its flash chip and figure out the partition bounds later. Dunno about the situation with other phones but given that many cheap Androids run Mediatek, it's not very difficult to claim a huge number of "crackable phones". The only thing that should protect you from any kind of government snoops is encrypting your phone with a strong passphrase and shutting it off once you leave a room taking the cops less than 30 seconds to enter.
- bobbob1 10y agoCellebrite is not that good at their job. They employ a few 0days for a few Android bootloaders, but in general most of their vulnerabilities used for extraction are either shitty or taken from the public which means if you have a fully patched Android device you're ok. Owning a brand new IPhone 7 with SEP and encryption on would make them useless, for now. A while ago there was a "leakage" which also included a few things which weren't supposed to be in the regular interwebs, while the files were quickly removed from their servers, a few people have managed to get what is needed. On the other hand, remember that cellphones nowadays are quite fragile and should be used with caution regarding any sensitive information, if you have something important better keep it somewhere else, not on your cellphone. This article is just a lame effort of their new "research", (more like PR), group manager to promote them, which he does in a perfect way, if only he had a proper job.
- st3v3r 10y agoI mean, with Trump's administration banning cybersecurity and encryption, this company should go out of business soon, right?
- bobbob1 10y agoThere are enough extreme regimes, (Mexico, Iran and other ex-USSR), who are willing to pay money to spy on their citizens.
- fredgrott 10y agoit would be somewhat hard to ban math, right? Take Trump's mouth blast with a grain of salt, as its not what he will end up doing once he learns what he is talking about.
- brianpan 10y agoThis is completely off-topic, but can we take a moment and recognize how fantastic it is that the article has a picture of a hacker's desk with an assortment of mobile devices like: a calculator, 3 bluetooth mice, and a stapler?!
- deleted 10y ago[deleted]
- jwildeboer 10y agoPR based self-marketing article is just that. "Be Very Afraid" hyperbole AFAICS.
- zuggywugg 10y agoJust going to leave this here: "New and improved modern UI" https://www.youtube.com/watch?v=QDkOxnSTUMY https://www.youtube.com/watch?v=QDkOxnSTUMY
- arca_vorago 10y agoOn a similar note, back when cell phones were just getting started, I started parsing the ownership of the cell towers. I noticed an unusually high correlation of Israeli companies owning them (back before the phone companies themselves really started investing in them). Now think about the purpose of an imsi catcher/stingray. The Israelis seem to be on the edge of cybersecurity across the board. I know while in Iraq I got lots of training that was decidely sourced from Israel too. All that being said, Israel is also known as being just as active if not moreso than Russia and China in their espionage against the US. I think that's also worth considering.
- defunctirl 10y agoAny specific resources/links re: that final comment? Not something I've ever read about, although I could imagine.. Not discrediting your statement, genuinely curious.
- arca_vorago 10y agoJust a quick duck duck go search returns these: http://foreignpolicy.com/2015/03/24/spy_vs_spy_america_and_israel_edition/ http://foreignpolicy.com/2015/03/24/spy_vs_spy_america_and_i... http://www.newsweek.com/2014/05/16/israel-wont-stop-spying-us-249757.html http://www.newsweek.com/2014/05/16/israel-wont-stop-spying-u... http://www.counterpunch.org/2009/03/12/israeli-spying-in-the-united-states/ http://www.counterpunch.org/2009/03/12/israeli-spying-in-the... http://www.timesofisrael.com/new-nsa-document-highlights-israeli-espionage-in-us/ http://www.timesofisrael.com/new-nsa-document-highlights-isr...
- defunctirl 10y agoCheers!
- deleted 10y ago[deleted]
- test_pilot 10y agoAnd somehow I can't connect my android phone to a mac computer with a USB cable to copy photos out, without it crashing 50% of the time. I must be missing something