9 ms·
> In completely unrelated news, upcoming versions of Signal will be periodically fetching files to place in app storage. These files are never used for anything
by paddlesteamer 5y ago
> In completely unrelated news, upcoming versions of Signal will be periodically fetching files to place in app storage. These files are never used for anything inside Signal and never interact with Signal software or data, but they look nice, and aesthetics are important in software.
I wish I could see those files in action...
- tony101 5y agoI wonder if the intention here is to deter Cellebrite from parsing Signal files? Or to pressure them into fixing their security vulnerabilities?
- hprotagonist 5y agoor just flipping them off, which seems OK too.
- jjoonathan 5y agoNah, Cellebrite will panic for a bit at the possibility of facing repercussions but ultimately not commit enough effort to change anything. Cellebrite's counterparties, however, might not be so complacent.
- kbenson 5y agoFiles will only be returned for accounts that have been active installs for some time already, and only probabilistically in low percentages based on phone number sharding. We have a few different versions of files that we think are aesthetically pleasing, and will iterate through those slowly over time. Pretty sure it's the former, since the above is a way to ensure that Cellebrite can't just gather all implied exploit files and make sure they've got those specific problems all patched. This is, quite literally, an informational attempt at guerilla/asymmetric warfare, where Signal is trying to make engaging with them too costly, while also making a few blows quite a bit above their weight level. Cellebrite now has to decide whether to keep after this adversary that both is hard to pin down, ambushes them, and has shown it can hit them really hard where it matters (credibility, and thus their pocket book).
- Zarathust 5y agoThis indeed looks like a FUD statement, implying that they can have an infinite amount of potential vulnerabilities. Realistically though, writing parsers that do not yield control of your whole device is not that complex. The people exploiting iOS zero days can certainly do it.
- kevinmchugh 5y agoIt's not that hard but neither is shipping patched versions of ffmpeg. This company will have some catching up to do.
- da_big_ghey 5y agothe signal are capable for finding more exploit with more time. important piece is that exists now a reasonable doubt on data from the celebrite, so it are not so good for evedince.
- Karunamon 5y agoYou're not wrong at all, but if they're shipping these garbage ancient versions of ffmpeg, there are likely oodles of other bugs lurking around. And, if Cellebrite acts like most other companies who've had their awful security exposed, they will fix only this bug and leave everything else.
- spoonjim 5y agoBut it might be easier for Cellebrite to just stop exfiltrating data from Signal. Of course, other apps could discover similar vulnerabilities.
- chopin 5y agoThat's not enough. With file system permission, Signal could place files anywhere (like prepared gifs in the Pictures folder). I think this taints any phone having Signal installed.
- alfiedotwtf 5y agoSignal should generalise this into a library so that other app vendors can include these perfectly cromulant files
- simonh 5y agoThat would reveal all the exploits to Cellebrite, which Signal is trying to avoid.
- FridayoLeary 5y agoI imagine many brother app vendors, who may or may not maintain good relationships with Signal might possibly have found a usb drive containing the relevant data on the street. (pure speculation, i don't know anything about moxie, but judging by his tone, i wouldn't be shocked)
- alfiedotwtf 5y agohehe. Now imagine if Hack Back laws actually passed... companies like Whisper Systems would have had impunity for even more shenanigans :)
- supergirl 5y agosignal wants to pick a fight with a grey company that gets money for cracking apps? not a good idea
- da_big_ghey 5y agoone could view make of an e2e encrypt app that is cause problem for polices as "not a good idea" but there must be some person for to do it.
- kevinyew 5y agoThey're already picking a fight with Cellebrite simply by existing, as Signal is antithetical to everything that Cellebrite stands for.
- barbazoo 5y agoI don't get it, can anyone elaborate on what they are talking about there?
- TheGeminon 5y agoThey are implying that future versions of Signal will drop random files on your phone that "may or may not" cause damage to Cellebrite systems. They are basically putting the threat out that if you use Cellebrite on Signal in the future, you might not get the data you expect, and at worst, it may corrupt the report/evidence. This also brings into question the chain of custody, as an untrusted device being imaged can alter reports of unrelated devices.
- franga2000 5y agoDamn, a chain of custody where the thing in evidence is also part of not only its own chain but also those of other evidence acquired afterwards? I can't imagine what kind of case law exists around that, but I'm sure it's hilarious!
- cosmie 5y ago> also those of other evidence acquired afterwards And prior extracts on the device.
- deleted 5y ago[deleted]
- elliekelly 5y agoWhich is what I don't really understand - it seems like Cellebrite could spin this in their favor so law enforcement would need to purchase a new kit for each device?
- rodgerd 5y agoSignal is going to start attacking third-party tools once it's installed on your phone. It's as though Theo decided that OpenSSH should respond to portscanners by trying to pwn the source systems.