20 ms·
Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer
- JulianMorrison 5y ago>We are of course willing to responsibly disclose the specific vulnerabilities we know about to Cellebrite if they do the same for all the vulnerabilities they use in their physical extraction and other services to their respective vendors, now and in the future. Mwahahahaha. Tell us how you hack our app and everyone else's, and we'll tell you how we hacked yours. The middle finger is strong with this one.
- deleted 5y ago[deleted]
- paddlesteamer 5y ago> In completely unrelated news, upcoming versions of Signal will be periodically fetching files to place in app storage. These files are never used for anything inside Signal and never interact with Signal software or data, but they look nice, and aesthetics are important in software. I wish I could see those files in action...
- tony101 5y agoI wonder if the intention here is to deter Cellebrite from parsing Signal files? Or to pressure them into fixing their security vulnerabilities?
- hprotagonist 5y agoor just flipping them off, which seems OK too.
- jjoonathan 5y agoNah, Cellebrite will panic for a bit at the possibility of facing repercussions but ultimately not commit enough effort to change anything. Cellebrite's counterparties, however, might not be so complacent.
- kbenson 5y agoFiles will only be returned for accounts that have been active installs for some time already, and only probabilistically in low percentages based on phone number sharding. We have a few different versions of files that we think are aesthetically pleasing, and will iterate through those slowly over time. Pretty sure it's the former, since the above is a way to ensure that Cellebrite can't just gather all implied exploit files and make sure they've got those specific problems all patched. This is, quite literally, an informational attempt at guerilla/asymmetric warfare, where Signal is trying to make engaging with them too costly, while also making a few blows quite a bit above their weight level. Cellebrite now has to decide whether to keep after this adversary that both is hard to pin down, ambushes them, and has shown it can hit them really hard where it matters (credibility, and thus their pocket book).
- Zarathust 5y agoThis indeed looks like a FUD statement, implying that they can have an infinite amount of potential vulnerabilities. Realistically though, writing parsers that do not yield control of your whole device is not that complex. The people exploiting iOS zero days can certainly do it.
- kevinmchugh 5y agoIt's not that hard but neither is shipping patched versions of ffmpeg. This company will have some catching up to do.
- da_big_ghey 5y agothe signal are capable for finding more exploit with more time. important piece is that exists now a reasonable doubt on data from the celebrite, so it are not so good for evedince.
- Karunamon 5y agoYou're not wrong at all, but if they're shipping these garbage ancient versions of ffmpeg, there are likely oodles of other bugs lurking around. And, if Cellebrite acts like most other companies who've had their awful security exposed, they will fix only this bug and leave everything else.
- alfiedotwtf 5y agoSignal should generalise this into a library so that other app vendors can include these perfectly cromulant files
- simonh 5y agoThat would reveal all the exploits to Cellebrite, which Signal is trying to avoid.
- FridayoLeary 5y agoI imagine many brother app vendors, who may or may not maintain good relationships with Signal might possibly have found a usb drive containing the relevant data on the street. (pure speculation, i don't know anything about moxie, but judging by his tone, i wouldn't be shocked)
- alfiedotwtf 5y agohehe. Now imagine if Hack Back laws actually passed... companies like Whisper Systems would have had impunity for even more shenanigans :)
- supergirl 5y agosignal wants to pick a fight with a grey company that gets money for cracking apps? not a good idea
- da_big_ghey 5y agoone could view make of an e2e encrypt app that is cause problem for polices as "not a good idea" but there must be some person for to do it.
- kevinyew 5y agoThey're already picking a fight with Cellebrite simply by existing, as Signal is antithetical to everything that Cellebrite stands for.
- barbazoo 5y agoI don't get it, can anyone elaborate on what they are talking about there?
- TheGeminon 5y agoThey are implying that future versions of Signal will drop random files on your phone that "may or may not" cause damage to Cellebrite systems. They are basically putting the threat out that if you use Cellebrite on Signal in the future, you might not get the data you expect, and at worst, it may corrupt the report/evidence. This also brings into question the chain of custody, as an untrusted device being imaged can alter reports of unrelated devices.
- franga2000 5y agoDamn, a chain of custody where the thing in evidence is also part of not only its own chain but also those of other evidence acquired afterwards? I can't imagine what kind of case law exists around that, but I'm sure it's hilarious!
- cosmie 5y ago> also those of other evidence acquired afterwards And prior extracts on the device.
- deleted 5y ago[deleted]
- elliekelly 5y agoWhich is what I don't really understand - it seems like Cellebrite could spin this in their favor so law enforcement would need to purchase a new kit for each device?
- rodgerd 5y agoSignal is going to start attacking third-party tools once it's installed on your phone. It's as though Theo decided that OpenSSH should respond to portscanners by trying to pwn the source systems.
- Nextgrid 5y agoSo I wonder, why disclose this? This will just prompt Cellebrite to improve its security process and sandbox the entire tool. If they wanted to destroy the credibility of the tool, using the vulnerabilities to silently tamper with the collected data or even leaking it online would be a much better option and hit them without any warning, not only jeopardizing those cases but forever casting doubt on not just Cellebrite but their competitor tools.
- godelski 5y agoAny court case where Cellebrite's tools have been used are now in jeopardy since the defence can just say that they were hacked by someone else. There's now reasonable doubt that Cellebrite can't be trusted. This damages their reputation with governments too.
- tptacek 5y agoNot really. The same circumstances exist for almost all digital evidence. Of course, a lot of Cellebrite usage is extrajudicial already.
- godelski 5y agoIf you're failing some basic security it isn't going to give much confidence. But also users don't know now if their systems will explode if they try to gather Signal (or other app) data.
- tptacek 5y agoThe quality of forensics software is extremely low; a similar story was once written about EnCase, and had zero impact on any legal case anywhere.
- polar 5y agohttps://insights.sei.cmu.edu/blog/forensics-software-and-oracle-outside-in/ https://insights.sei.cmu.edu/blog/forensics-software-and-ora... ?
- po 5y agoThis is truly a hacker’s retort. It attacks Cellebrite's ability to operate by casting doubt on the reports generated by the product that their customers may wish to use in court. It places them in legal peril from Apple, and removes any cover Apple would have to not take legal action. (I assume someone at Apple knew they were shipping their DLLs?) It makes a thinly-veiled threat that any random Signal user's data may actively attempt to exploit their software in the future and demonstrates that it's trivial to do so. edited to add a bonus one: Publish some data about what they are doing to help create a roadmap for any other app that doesn't want their data to be scanned.
- ASalazarMX 5y agoAll that trouble becaused a bag conveniently "fell from a truck". All in all I'm really happy for all this.
- ampdepolymerase 5y agoIndeed, how convenient. If it truly did fall off the truck right while he is on a walk then there is the possibility that is a rubber duckie attack. This is basically the equivalent of leaving a USB flash drive lying around. I hope the author took the necessary precautions when reverse engineering the device. Companies like cellebrite have deep connections to certain three letter communities that staging this sort of attacks trivial.
- CPLX 5y ago> If it truly did fall of the truck lol
- baby 5y agoSeeing reactions like GP’s I’m surprised at how many people don’t know this expression.
- ASalazarMX 5y ago
- upofadown 5y agoThey literally said the unit fell off a truck. Funny... Correctly me if I am wrong, but did they really say they were going to be doing active attacks against Cellebrite units? Also funny... but they probably are not actually going to be doing that.
- kbenson 5y agoThey didn't actually say anything of the sort. They may have implied some stuff. Anything they did imply wouldn't be an active attack though, it would be a passive one, triggered only if Cellebrite tried to gather data from the Signal app on phones. Not gathering info from a phone, or not gathering Signal data from a phone, would both be ways Cellebrite could avoid this potential passive attack.
- ASalazarMX 5y agoThe digital equivalent of "stop hitting yourself". Notwithstanding their crypto issue, this gives me renewed confidence in Signal's team.
- pavon 5y agoTo me it seems more like the equivalent of leaving booby trapped packages to be found by porch pirates. Or putting laxatives (or worse) in your sandwich to get back at the unknown coworker stealing your lunch. Both of which are considered illegal in the US. Assuming these files actually contain exploits. Maybe they do maybe they don't. You feeling lucky Cellebrite?
- phyzome 5y agoThe question of whether damaging reports would be illegal is separate from whether booby traps are illegal. And they're not, in the broad case: Booby trapped packages are only illegal if they cause bodily harm or damage or are negligent along those lines.
- 5y ago
- amluto 5y agoNow if only I could use legitimate tools to access my own Signal data on an iOS device.
- NullPrefix 5y agoHave you tried going out for a walk and looking for trucks with small packages falling off?
- gruez 5y agodoesn't an itunes backup contain all the app data?
- mike_d 5y agoI own a Cellebrite, and yeah you are right. The Cellebrite box is nothing other than a phone backup tool. The nice thing it does is implement every backup sync protocol for every version of every mobile OS so you don't have to spend a whole day trying different combinations of iTunes and such. The "Physical Analyzer" is just a forensics tool. There are dozens of competitors out there that will take a phone and surface the things that might be interesting in a court case or law enforcement investigation. The product Signal didn't talk about - which I think is the one they are upset about - is Cellebrite Premium. That is their service where law enforcement can send locked or damaged devices to their lab and get back a an image to load into PE. However in 99% of cases devices are either accessed because they are running old software with public vulnerabilities, or using the magic phrase "would you mind unlocking your phone so we can clear this matter up?"
- sitzkrieg 5y agoi find it remarkably unbelievable someone would put a cellebrite bag in the back of a truck given the price alone.. and the timing too. sure
- NullPrefix 5y agoI bet the tool was bought from a supplier but Signal team can't disclose it because source protection.
- marcopet 5y ago"fell off the back of a truck" is an idiom [1]. It's not meant literally. [1] https://www.phrases.org.uk/meanings/fell-off-the-back-of-a-truck.html https://www.phrases.org.uk/meanings/fell-off-the-back-of-a-t...
- ampdepolymerase 5y agoIt's like "a little bird told me".
- myself248 5y agoThe "parallel construction" of the civilian world.
- supergirl 5y ago
- marcodiego 5y ago> One way to think about Cellebrite’s products is that if someone is physically holding your unlocked device in their hands, they could open whatever apps they would like and take screenshots of everything in them to save and go over later. Cellebrite essentially automates that process for someone holding your device in their hands. Aren't Cellebrite products/services more advanced than that? I mean don't they use publicly unknown zerodays to extract data from locked phones?
- deleted 5y ago[deleted]
- sodality2 5y agoThey are more advanced typically than just extracting data from a phone. Not sure to which extent they advertise it brazenly though. Fairly certain they blog about it a lot
- carstenhag 5y agothe cellebrite ambassador we talked to (as private company) basically bragged they were the ones that unlocked the San Bernadirno iPhone. I'm sure towards government officials and Law Enforcement they brag even more.
- saagarjha 5y agoBut they weren’t, that was Azimuth: https://www.washingtonpost.com/technology/2021/04/14/azimuth-san-bernardino-apple-iphone-fbi/ https://www.washingtonpost.com/technology/2021/04/14/azimuth...
- carstenhag 5y agoHm, interesting. So there are articles saying it's Cellebrite https://www.reuters.com/article/us-apple-encryption-cellebrite-idUSKCN0WP17J https://www.reuters.com/article/us-apple-encryption-cellebri..., then others saying it was unmentioned professional hackers and then your article where all three possibilities are mentioned.
- tazeg95 5y ago"I was recently out for a walk when I saw a small package fall off a truck ahead of me."... I I laughed :)))
- hnrodey 5y agoI have a new found perspective for the malware/spyware industry after watching The Dissident. I am SO IMPRESSED with this middle finger from the Signal team. https://www.imdb.com/title/tt11382384/ https://www.imdb.com/title/tt11382384/
- p4bl0 5y agoI hope Cellbrite users like the rhythm and lyrics of Never gonna give you up.
- throwaway888abc 5y agoBy a truly unbelievable coincidence, I was recently out for a walk when I saw a small package fall off a truck ahead of me. Nailed it!
- xchip 5y agoAny idea what this means? It is at the bottom of the article: "In completely unrelated news, upcoming versions of Signal will be periodically fetching files to place in app storage. These files are never used for anything inside Signal and never interact with Signal software or data, but they look nice, and aesthetics are important in software.[...]"
- tptacek 5y agoThey're alluding to the fact that they can randomly pop Cellebrite installations by planting anti-Cellebrite malware on their users phones.
- WrtCdEvrydy 5y agoThis is something I have personally looked at as an owner of a UFED touch device (1st gen). By default your software runs in a non-priviledged account but who's to say one of files isn't just straight up being read by FFMPEG and adding or removing evidence from the final report. The official Cellebrite policy has always been "don't worry, if you get stuck, we can send you an expert to testify to the reliability of the scientific evidence due to previous cases" but what happens when the pyramid of previous cases fall apart? Do you suddenly own a paperweight? I've also published papers (with NIST's help) on using consumer grade hardware for forensics and why testing your tools across a wide variety of scenarios is critical.
- tediousdemise 5y ago> As just one example (unrelated to what follows), their software bundles FFmpeg DLLs that were built in 2012 and have not been updated since then. This purported vulnerability does not rely on FFmpeg, hence the disclaimer.
- idlewords 5y agoThis is pretty irksome. I get how satisfying it must feel, but the one thing I want as a Signal proponent is for the app to be boring and reliable. That means make it easy to use enough to be mainstream, squash bugs, and do all the lovely security work you do. That does not mean adding stuff like untraceable cryptocurrency payments or very publicly tweaking the noses of law enforcement, and bragging about how you're putting exploits in your app to hack them. This isn't 1993 and the last thing we need is more pretexts to ban E2E encrypted apps in the countries where they're needed the most. I think this trades a moment's satisfaction for a very bad long-term outcome.
- jjoonathan 5y agoSignal isn't going to actually do it, they know how that would end, they're just playing the FUD game in the other direction. Which I am 100% on board with.
- idlewords 5y agoMaybe the one thing worse than boasting that you're putting malware in your product is boasting about it and not doing it.
- deleted 5y ago[deleted]
- mannerheim 5y agoIs it malware if users desire for their devices to be resistant to surveillance tools?
- spinny 5y agogoodware ??
- PeterisP 5y agoThose are not related issues - it's malware or not malware based on what it does or did (e.g. did it corrupt data on someone else's computer system because it was intended to do just that thing?) regardless of the reason for placing it there. If you can't figure out a way to satisfy your desire for your devices to be resistant to surveillance tools with legal means, well, then you can't satisfy that desire. Furthermore, not only the ends don't justify the means, the ends can be prohibited too - if you explicitly design something to destroy your own data knowing that this data would get used in a criminal investigation, that may be a crime on its own (tampering with evidence/obstruction of justice, location matters of course); you don't have to testify against yourself, but destroying evidence is a crime even if it's your property (e.g. throwing your gun into a river after a shooting so it wouldn't be found) and furthermore in that case the court may be allowed to assume that the destroyed evidence was unfavorable to you, that the data contained the damning things they expected to find there - so if you want to protect your devices from surveillance tools operated with a legal warrant, you might want to consult a lawyer to find out if that's a good idea in your jurisdiction, it may well be worse for you than doing nothing.
- colmmacc 5y agoAs a Signal user and moxie fan I love that post, but I worry that it places Signal in legal peril from Apple. My fear, and prediction, is that the authorities will frame this as an even more egregious attack on law enforcement and that interfering with investigations is a crime (I'm not a lawyer, but I play one in hacker news comments, and that sounds like a crime). They'll lean on the app stores and the app stores will lean on or remove Signal.
- jjoonathan 5y ago1. Any app could do it. 2. Signal stirred FUD in a blog post. That's a very different thing from actually doing it.
- jaywalk 5y agoWell, if you read the whole blog post, it certainly seems like they're actually doing it.
- jjoonathan 5y agoNah. The cost/benefit of saber rattling makes tons of sense while the cost/benefit of actually doing it makes much less sense. Probably. No amount of certainty about Marlinspike's actions should comfort Cellebrite, though, because Moxie Marlinspike isn't the only person allowed on the app store.
- akerl_ 5y agoI’m not sure what you mean. The end of the post pretty clearly describes the framework they’re using to roll out these exploits as latent files within the Signal app.
- twright0 5y agoThe end of the post is extremely specifically and carefully not describing a framework for rolling out files to exploit these vulnerabilities; those files as described do nothing, and serve only aesthetic purposes. While it's easy to read that as a wink that they are exploiting the vulnerabilities they found while maintaining plausible deniability that they aren't, it's equally possible it's the other way around: they aren't rolling out exploits but want people reading the blog post to believe that they are. Or that they want to lay out the framework so that others can do so, but aren't actually going to follow through themselves. As written it's essentially unverifiable, obviously on purpose.
- tony101 5y agoA reminder that you can pair lock your iPhone to prevent analysis by Cellebrite or similar tools: https://arkadiyt.com/2019/10/07/pair-locking-your-iphone-with-configurator-2/ https://arkadiyt.com/2019/10/07/pair-locking-your-iphone-wit...
- Anechoic 5y agoDo we (reasonably) know if this still works?
- lights0123 5y agoThere was a vulnerability in this technique that was fixed in iOS 11: https://labs.f-secure.com/advisories/apple-ios-host-pairing-bypass/ https://labs.f-secure.com/advisories/apple-ios-host-pairing-.... If someone found another vulnerability and shared it with Cellebrite, then it doesn't work. If they haven't, then it still does.
- atVelocet 5y agoThis still works as written. Just test it yourself with a Mac and Apple Configurator.
- Gaelan 5y agoI mean, “the iPhone prevents well-behaved software from accessing data without a password” and “software, known to exploit vulnerabilities to get around security features, currently doesn’t have any such exploits” are very different.
- ASalazarMX 5y agoEvery stone we can put in the way of surveillance helps.
- Anechoic 5y agoMy question was ambiguous, what I meant was whether or not there were any known exploits to work around pair locking (all of my iOS devices are pair-locked). I didn't know about the exploit that lights0123 linked to, but it appears that has been fixed.
- rubatuga 5y agoTruly a jaw dropping blog post, as the top comment currently states, Apple may be legally required to at the very least, comment on this situation.
- DaiPlusPlus 5y ago> Apple may be legally required to at the very least, comment on this situation. "Required" to comment? By whom and for what reason?
- oh_sigh 5y agoSending a cease and desist to Cellebrite for shipping their DLLs in their product I imagine. Obviously there may be some backchannel, but that is probably how it would go if you assume Apple and Cellebrite have no relationship.
- mintplant 5y agoThey could send such a C&D, and they may be inclined to for the sake of public perception, but what would "legally require" them to do so?
- chordalkeyboard 5y agoIf they ignore cellebrite using their stuff they may have waived their right to be upset about someone else doing the same thing.
- DaiPlusPlus 5y agoCopyright law isn't the same thing as Trademark law. Copyrights don't expire because the rightsholder failed to enforce their rights, only trademarks do.
- Y_Y 5y ago
- Klonoar 5y agoIf it's true that you can grab a Cellebrite hardware piece without too much difficulty (Ebay, etc - and note I'm not speaking from expertise so someone please fact check me), I'd find it hard to believe Apple wouldn't have done this kind of inspection themselves and/or noticed those DLLs being shipped. Curious if there'll be a response of sorts.
- polar 5y agoI am reasonably confident that Apple is a Cellebrite customer. Their security team certainly has access to forensic tools from other vendors. That team also spawned BlackBag Technologies, which is now part of Cellebrite.
- saagarjha 5y agoApple uses Cellebrite devices in their stores to transfer data from devices, I believe.
- Ansil849 5y agoI don't understand the seeming incongruity between these two statements: On the one hand: > One way to think about Cellebrite’s products is that if someone is physically holding your unlocked device in their hands, they could open whatever apps they would like and take screenshots of everything in them to save and go over later. Cellebrite essentially automates that process for someone holding your device in their hands. But on the other hand: > We are of course willing to responsibly disclose the specific vulnerabilities we know about to Cellebrite if they do the same for all the vulnerabilities they use in their physical extraction and other services to their respective vendors, now and in the future. If UFED just copies data from unlocked phones, why would they be using vulnerabilities to do so? I guess my question is, is Cellebrite capable of copying locked devices, or more to the point - has vulnerabilities to unlock devices without knowing the access PIN?
- g_sch 5y agoBased on the post, it sounds like there's some data parsing going on (possibly to present the data in a user-friendly way?), and the parsing step uses outdated versions of software (such as ffmpeg) which have well-documented vulnerabilities in them.
- md_ 5y agoCellebrite claims, "Lawfully access locked devices with ease Bypass pattern, password or PIN locks and overcome encryption challenges quickly on popular Android and iOS devices" https://www.cellebrite.com/en/ufed/ https://www.cellebrite.com/en/ufed/
- supergirl 5y agothey could use vulnerabilities to extract more data. probably it's common to do some obfuscation of data which celebrite might have reverse engineered.
- dandelany 5y ago> is Cellebrite capable of copying locked devices, or more to the point - has vulnerabilities to unlock devices without knowing the access PIN? Yes, they even brag about it in their marketing materials: https://www.cellebrite.com/en/a-practical-guide-to-checkm8/ https://www.cellebrite.com/en/a-practical-guide-to-checkm8/ That's a public vunerability, it's anyone's guess how many nonpublic ones they're using.
- crb002 5y agohttps://www.iowajustice.com/ https://www.iowajustice.com/ is amazing at UFED defense.
- motohagiography 5y agoWow, that video made my day. This bit is key: > "For example, by including a specially formatted but otherwise innocuous file in an app on a device that is then scanned by Cellebrite, it’s possible to execute code that modifies not just the Cellebrite report being created in that scan, but also all previous and future generated Cellebrite reports from all previously scanned devices and all future scanned devices in any arbitrary way (inserting or removing text, email, photos, contacts, files, or any other data), with no detectable timestamp changes or checksum failures. This could even be done at random, and would seriously call the data integrity of Cellebrite’s reports into question." They've may have just got a lot evidence collected using Cellebrite from phones with (or without) Signal installed on them thrown out of court. I don't recall the details, but there was an absolute unsubstantiated speculative and surely fictional rumor of at least one entirely theoretical zero-day non-gif formatted image file that exploited a similar class of vulnerability in what was probably not a market leading tool used tangentially for the same purposes, floating around well over a decade ago as well. I for one am very glad that these hypothetical issues have almost surely been fixed.
- ZeroCool2u 5y agoThe video made my inner child feel truly vindicated with my choice of username.
- kstrauser 5y agoI’m envious.
- kstrauser 5y ago…of your awesome username. I wasn’t being snarky!
- acidburnNSA 5y agoSame here.
- 5y ago
- cycomanic 5y ago>By a truly unbelievable coincidence, I was recently out for a walk when I saw a small package fall off a truck ahead of me. As I got closer, the dull enterprise typeface slowly came into focus: Cellebrite. That's just hilarious! Nice way of saying we got our hands onto one of these boxes, but we don't want to reveal how. It fell of a truck.
- chonkywonk 5y agoApple uses Cellebrite devices in its own stores.
- joshgoldman 5y agoI like how the CEO bashes other countries and deliberately doesn't mention USA as a customer of Cellebrite
- maybelsyrup 5y agoThis rocks so hard. Also the Prodigy soundtrack! Takes me back.
- alfiedotwtf 5y agoHack the Planet o/
- alfiedotwtf 5y agoDamn. That video say it all.
- tGr5lGf7 5y agoCellebrite doesn't even have a bug bounty programme or contact to report their bugs. Last year I've managed to gain partial access to one of their systems and it took me weeks emailing their internal email addresses to finally fix the bug. They were total ass about it. Now I've got complete access to their entire database and I don't know what do. Can HN advise?
- kjjjjjjjjjjjjjj 5y agoYou should not treat an unethical company ethically.
- thricegr8 5y agoPost is here and let folks take a look.
- exikyut 5y agoReally REALLY bad idea - this is one of law enforcement's larger pet gadgets and companies, so the GP would not only have a particularly enthusiastic mob coming after them, said mob's pitchforks would have automatic cannon launchers and EMPs and push-button-activated nunchucks and all kinds of other crazy things that aren't legal for standard-issue pitchforks. So if the database is fingerprintable to the GP specifically in any way, they're very very dead. And the random username doesn't even count here; they probably didn't post from Tor, so their real IP is connected to this post.
- qyi 5y ago>Since almost all of Cellebrite’s code exists to parse untrusted input that could be formatted in an unexpected way to exploit memory corruption or other vulnerabilities in the parsing software, one might expect Cellebrite to have been extremely cautious. >Looking at both UFED and Physical Analyzer, though, we were surprised to find that very little care seems to have been given to Cellebrite’s own software security. People keep saying this. It has never changed since the 90s. There is no bar to become a "software engineer".
- systemvoltage 5y ago> By a truly unbelievable coincidence, I was recently out for a walk when I saw a small package fall off a truck ahead of me. As I got closer, the dull enterprise typeface slowly came into focus: Cellebrite. Inside, we found the latest versions of the Cellebrite software, a hardware dongle designed to prevent piracy (tells you something about their customers I guess!), and a bizarrely large number of cable adapters. Does anyone find a package dropping off a truck and first take a picture of it, pick it up and go home to open it? Even if someone picks up the package, usually taking a picture of it doesn't come to their mind. It's an unsual bit in the story. Unless, they went back and put the bag on the road to show that it was found just for the sake of "recreating the story" purposes. How does something like a small briefcase just "fall from a truck"? By what mechanism? Briefcase would be stored inside the cabin. If you're the author, can you explain my suspicion?
- frabjoused 5y agoIt's a joke.
- systemvoltage 5y agoSorry, please go ahead and downvote my comment so its not cluttering up :)
- bodhi 5y agoIts a loquacious take on “fell off the back of a truck”.
- matteotom 5y ago“Fell off the back of a truck” is usually a metaphor for either stolen or otherwise acquired in a way they don’t want to explain.
- systemvoltage 5y agoThanks, I didn't catch this.
- 5y ago
- hellothestateis 5y agokmk
- swyx 5y agomy TL;DR (but its a damn good read and funny too) - Cellebrite helps oppressive regimes read your messages - Signal keeps your messages private - Cellebrite announces "Signal support" - Signal finds 9 years of vulnerabilities in Cellebrite - Signal permanently pwns Cellebrite You come at the king, you'd best not miss.
- tediousdemise 5y agoTo be fair, this vulnerability disclosure is worthless, because it wasn’t actually disclosed—the true vulnerability is purported to be in the file that Signal uses to execute arbitrary code, of which the details are not shared. We are relying on pure trust that the video demonstration of the purported vulnerability is not a forgery. Additionally, I see from the video that the purported vulnerability is present in UFED version 7.40.0.229. There is nothing stopping Cellebrite from patching this purported vulnerability, and shipping trustworthy versions of UFED going forward. If there is a concern that the purported vulnerability still exists, the burden of proof will be with the person claiming the vulnerability exists, for each new version of UFED. Cellebrite doesn’t even need to implement actual code, but merely increment the UFED version number. It will be an endless cat and mouse game driven by baseless claims from both sides. Since this vulnerability has not been reproduced by third parties, it could be equally likely that Signal is using a psyop rather than exploiting a genuine vulnerability. In either scenario, it casts doubt on Cellebrite; the damage is done by convincing you, the reader.
- sneak 5y agoMany vulnerabilities are disclosed without simultaneous disclosure of the PoC. That doesn't make it worthless. Also, not disclosing specifics is reasonable here, given that the vendor is themselves known for using, hoarding, and selling access to 0days. There is no obligation for a researcher to share their research with such a corrupt vendor.
- tediousdemise 5y agoI agree that the vendor is detestable, but we must decouple that sentiment from the idea that this blog post compromises Cellebrite’s product or credibility in any way. As it stands, the vulnerability is not reproducible by anyone other than Signal. Reproducibility is key in the scientific method and in the court of law.
- amscanne 5y agoThe post seems to provide a straight-forward map to at least one vulnerability. If they have FFMPEG DDLs that have not been updated since 2012 and they are used on files found on the file system, you just need to find a relevant vulnerability and craft an appropriate media file. These vulnerabilities are well-known and well-documented. It just doesn't point to the specific DLL & CVE, but otherwise seems like it would be relatively easy to figure out.
- sathackr 5y agoCellebrite's initial response[1] includes this gem "We have strict licensing policies that govern how customers are permitted to use our technology and do not sell to countries under sanction by the US, Israel or the broader international community." And these policies are obviously quite effective at preventing such uses. [1] https://www.theregister.com/2021/04/21/signal_cellebrite/ https://www.theregister.com/2021/04/21/signal_cellebrite/
- FridayoLeary 5y agoah. Those must also be modules that fell from the truck.... (these companies clearly have trucks like sieves) I have no doubt that already, cellebrite are on the phone ordering more secure, err 'trucks'
- philshem 5y agoI'd also like to get really excited about this. Can someone ELI5?
- akerro 5y agoThis isn't the first time moxie0 found something important on a street, is it?
- temptemptemp111 5y agoAmazing that no security minded people even consider Moxie & Cellebrite being in cahoots. "But that's anti-semitic!" Take your head out of the sand and realize that this doesn't apply to 98+% of "semitic" people, by definition.
- qwertox 5y ago> Also of interest, the installer for Physical Analyzer contains two bundled MSI installer packages named AppleApplicationsSupport64.msi and AppleMobileDeviceSupport6464.msi. These two MSI packages are digitally signed by Apple and appear to have been extracted from the Windows installer for iTunes version 12.9.0.167. Couldn't Apple now sue Cellebrite?
- the_lucifer 5y agoYup, Signal just handed Apple's lawyers a loaded gun. Who knew I'd be enjoying Signal and Apple tag-teaming Cellebrite.
- qwertox 5y agoI wonder if they will. That would show it their "our customers privacy is the most important thing for us"-stance is something which they seriously mean.
- mot0man 5y ago"Fell off a truck" for those who don't get that it was a joke, the software is available for download on some non legal channels, you just need to look. He doesn't want to reveal the origin.
- joeblau 5y agoSignal is almost like anti-virus software against Cellebrite.
- not1ofU 5y agoHow do Cellebrite maintain "Chain of custody"? If they need to modify (hack) the device to get access. I was of the understanding, that if any file is modified then "chain of custody" is no longer in good standing, and therefore cannot be used as evidence.
- psd1 5y agoYou wish. All they need to do is track which files they modify and not touch the other ones. I doubt it would be fruitful to explore that angle in court
- not1ofU 5y agoI attended a conference back in the early 00's, where a member of GHCQ presented. He spoke about assisting on 911, obtaining forensic evidence from hard drives and the lengths that his team had to go to, to make sure that no files where changed while creating a clone of the drives. He stated that they can not just turn on a computer when they have seized it, as there would be about 800 files altered before Windows had even booted to the login screen. This, he stated, would destroy the chain of evidence. He might have been full of shit though.
- amai 5y ago"These two MSI packages are digitally signed by Apple" Couldn't Apple simply revoke the signature?
- waltwalther 5y agoThis is a really great piece. I have two observations. 1) "..saw a small package fall off a truck ahead of me..." 2) The very last paragraph is just great!
- Malp 5y agoWhile this report is entertaining to read, I have to wonder about possible downstream repercussions of the implications within the last paragraph; if you're in police custody or worse and your Signal app contains some 'aesthetically pleasing files' that interfere with the authoritarian software, it's likely going to be your ass on the line for all sorts of charges. Don't get me wrong, the implication is enough to discredit Cellebrite, but my initial thoughts are that either this bluff gets called, or there's a non-zero risk of someone landing in even hotter water down the line for using Signal. Of course, this assumes that you're not already neck-deep for having encrypted data and upholding your right to privacy.
- caeril 5y agoSomething about this smells a little off. If Moxie can get his hands on these devices and hack them, why can't Apple or Google, with all their resources, seem to be capable of REing them to fix the mobile device bugs they currently exploit? Tinfoil hat perspective suggests they don't want to.
- Ice_cream_suit 5y agoSignal have just added files to compromise Cellebrite to their default installation ! "In completely unrelated news, upcoming versions of Signal will be periodically fetching files to place in app storage. These files are never used for anything inside Signal and never interact with Signal software or data, but they look nice, and aesthetics are important in software. Files will only be returned for accounts that have been active installs for some time already, and only probabilistically in low percentages based on phone number sharding. We have a few different versions of files that we think are aesthetically pleasing, and will iterate through those slowly over time. There is no other significance to these files."
- cryptonector 5y ago> Since almost all of Cellebrite’s code exists to parse untrusted input that could be formatted in an unexpected way to exploit memory corruption or other vulnerabilities in the parsing software, one might expect Cellebrite to have been extremely cautious. [...] Yeah, but they probably figured they're not being attacked. But now? Now they'll have to figure they are.
- dredmorbius 5y agoCrossing the streams, the US Postal Inspectors Service (which hosts iCOP, detailed in a recent Yahoo story) are a Cellebrite customer: https://www.uspis.gov/wp-content/uploads/2020/02/FY-2019-annual-report-508-web.pdf https://www.uspis.gov/wp-content/uploads/2020/02/FY-2019-ann... (p. 35) See: https://news.ycombinator.com/item?id=26892180 https://news.ycombinator.com/item?id=26892180 https://news.yahoo.com/the-postal-service-is-running-a-running-a-covert-operations-program-that-monitors-americans-social-media-posts-160022919.html https://news.yahoo.com/the-postal-service-is-running-a-runni...