4 ms·
> In completely unrelated news, upcoming versions of Signal will be periodically fetching files to place in app storage. These files are never used for anything
by BasilPH 5y ago
> In completely unrelated news, upcoming versions of Signal will be periodically fetching files to place in app storage. These files are never used for anything inside Signal and never interact with Signal software or data, but they look nice, and aesthetics are important in software. Files will only be returned for accounts that have been active installs for some time already, and only probabilistically in low percentages based on phone number sharding. We have a few different versions of files that we think are aesthetically pleasing, and will iterate through those slowly over time. There is no other significance to these files.
I assume those images are going to be for the benefit of somebody looking at data extracted through Cellebrite?
- Y_Y 5y agoProbably they'll be the files that he talks about earlier which exploit the Cellebrite machine and fuck up all the reports. Or maybe it's just nothing.
- gnfargbl 5y agoIf this isn't merely a joke, and these proposed files are intended to contain Cellebrite exploits of some kind, then please, Moxie, let us have an opt out? As it stands, if law enforcement for some bizarre reason decide to examine my personal devices, there will be nothing on there of interest to them. If Signal start bundling exploits onto my device, that will no longer be the case. That's a potential risk to me, and Signal should be asking my permission before taking the risk.
- spaceribs 5y agoI probably broke 10 laws/regulations without knowing it just this morning before coffee, what makes you think you know you're "innocent"?
- celticninja 5y agoDont think of them as cellebrite exploits but as Signal security features. Yes you have nothing to hide, but the police in many cases aren't honest. What if you live in the Middle east and are gay, you use signal, this protects you. Cellebrite are happy to sell their product to oppressive regeimes and if you are black the US police could be considered oppressors.
- ISL 5y agoIf you're being oppressed by a repressive regime, having a phone that damages the oppressor's infrastructure may not have a positive outcome for you, the individual. "Hey, your phone corrupted our 'lawful' intrusion system. That violates a long list of statutes. We're going to beat you with this wrench now, because you made our day worse, and then charge you with crimes against the state."
- celticninja 5y agoIf they will beat you with a wrench for that they will beat you regardless of what is in your phone. If they do find something they dont like you get hit with the wrench, if they don't find anything you must be hiding it so you get beat with the wrench. So now we are saying don't protect yourself because if you do that would imply you have something to hide,and are therefore guilty and deserving of the wrench beating.
- ISL 5y agoMy concern is really, "Signal has a beef with Cellebrite, and so some unsuspecting and innocent person gets hit with a wrench." It is a different game if Signal makes the sharding opt-in. If someone vacuums my phone and it turns out that my treatise about Little Bobby Tables [1] breaks the vacuum, that is fine by me. [1] https://xkcd.com/327/ https://xkcd.com/327/
- celticninja 5y agoWe should all have beef with cellebrite. Have you seen their customer list? If they make it opt-in then surely that is worse for the user. Then the oppressive regime can say "you deliberately did this thing".
- ISL 5y agoThe older I get, the more I find myself reticent to impose my 'shoulds' (I have many :) ) upon others. It is a complicated world.
- thecrash 5y agoIn this (somewhat contrived) scenario where authorities are targeting your phone for surveillance solely to access a possible exploit file placed there by Signal, how would an opt-out option help you? Do you imagine that you could explain to the authorities that you opted out, and they would send you on your way? Or do you imagine that they would hold you personally responsible for the exploit, even though Signal has publicly taken credit for doing this?
- gnfargbl 5y agoThat is not the scenario I'm outlining. I am outlining a hypothetical scenario where the authorities choose to look through my phone for ${UNRELATED_REASON}, and the presence of Signal's hypothetical exploit files would cause their digital forensics software to crash. In this hypothetical scenario, that crash in and of itself could then be taken as a reason to charge me. I don't believe "the app software maker selected my phone at random to have those files on it!" would help me out in that situation; that's the sort of nuance that tends to get completely lost. The opt-out option would help me because, having opted out in advance, the hypothetical exploit files would not be on my phone. I do agree that this is a slightly far-fetched scenario. However, I am very confused how HN can generally be of the opinion that having unwanted malware on your phone is a good thing, even if Signal put it there.
- ellenhp 5y agoI think this is my first-ever comment on HN, and I'm basically just chiming in to say that under no circumstances should you even be talking to police in a situation like this. You can politely ask for a lawyer, politely ask if you're being detained and politely provide your basic information when asked like your name and address, but otherwise do not say anything at all. This fantasy that you can get away from a situation in which you are being interrogated and your phone is being searched by being compliant and proving your innocence to the nice police officers is extremely dangerous. Being compliant and providing information beyond what's legally required is the exact opposite of what you want to do, and preventing yourself from being charged should be the last thing on your mind. You should take it as a given that you will be charged. edit: If you're outside the USA ignore this advice and listen to someone more local who knows their stuff.
- deleted 5y ago[deleted]
- Silhouette 5y agoWhat's with all the downvotes? The parent is asking a reasonable question and making a reasonable request.
- ruined 5y agothere are plenty of things to fear in police custody and the police don’t need a reason like that for any of them. they will simply do it if they want.
- CleaveIt2Beaver 5y agoExcept there's no guarantee your phone will even contain a payload. Just the chance that some devices may have it, and there's no way to know for certain. And if they take in even one phone to scan that carries the exploit, it can make past, current and future evidence rendered untrustworthy. It's herd immunity via the prisoner's dilemma.
- aerophilic 5y agoI assume most likely these are being used to defeat/render ineffective one of Cellebrite’s features. By having other (benign) data travel alongside your data... it makes it harder for an attacker to know what data is “useful”.
- hatsunearu 5y agoNo... if you read the article carefully, the outline goes something like this: 1. We found a cellebrite kit that "dropped out from the back of a van" (yeah right lol) 2. Cellebrite is a tool to extract data out of phones (general intro to what Cellebrite is) 3. Looks like Cellebrite is using a bunch of open source libraries and they also use Apple DLLs (???!!!) 4. Oops looks like they are using like YEARS old libraries and there are hundreds of KNOWN vulnerabilities on each of those libraries. 5. Oops looks like the vulnerabilities allow ACE. Here's a demo where we placed a carefully crafted file with the ACE payload on a phone where if you just click the scan button on Cellebrite's software, you can do ACE (this is the video in the middle of the article) 6. (by the way for cellebrite users) this calls into question all data extracted with Cellebrite since these exploits are trivially exploitable. There are so many exploits possible so you can use any of them to create ACE attacks. 7. For COMPLETELY TOTALLY UNRELATED AESTHETIC REASONS we are putting some files on the Signal app. You're welcome! --- to spell it out: yes, they are putting ACE payloads on Signal to try to crash investigators/spies/whatever trying to use Cellebrite on phones with the Signal app.
- pieter_mj 5y agoI like 6 a lot, could be an avenue for legal refutation of obtained evidence (in a supposed crime or other illegal activity), 7 is a bit unnecessary.
- SAI_Peregrinus 5y agoNot at all! 7 is actually a lot more subtle, I didn't get it at first. They're putting some files on some signal phones, somewhat randomly, and only those which seem like they've been in active normal use since before this disclosure. So likely none of the devices Cellbrite might own for testing, and no device Cellbrite might buy in the future, but some random set of existing devices in the field. And there might be multiple such files, so even if Cellbrite find one they can't be sure they've got them all. Now assume these files are (as somewhat implied) exploits that cause the falsification of data in all current and future reports issued by a given Cellbrite device. That means that if a Cellbrite has, after this point, ever scanned a phone with Signal installed it might be issuing false reports. THAT means that there's a reasonable doubt in any evidence obtained by the use of a Cellbrite device, going forward. That gives an easy out to defense attorneys in the US, where Cellbrite devices are used by police to gather evidence. Any defense attorney can now argue that evidence obtained from a Cellbrite shouldn't be admitted in court, since they don't maintain forensic integrity. This essentially spoils Cellbrite's entire business in the US (and any other country with similar standards for the admissibility of evidence). So Cellbrite has to find ALL the exploits in their system, and be very, very sure they've not missed any. Because defense attorneys will then try to call that into doubt. Etc.