4 ms·
The article states "that corrupted apps on a targeted phone could basically overwrite any data extracted by Cellebrite’s tools" Traditionally a non volatile me
by georgeplusplus 5y ago
The article states "that corrupted apps on a targeted phone could basically overwrite any data extracted by Cellebrite’s tools"
Traditionally a non volatile memory chip is forensically read by being removed from the board and read out directly. Each sector is read from its memory registers. This is a robust forensic method since 1) its passive 2) its repeatable 3) you can fit the chip into another surrogate device and obtain the same results or use a different piece of software to obtain the results
If what cellebrite is doing is altering the memory when it interrogates it, this breaks the chain of custody. The process cannot be repeated.
- PeterisP 5y agoThe described cellebrite tool is not used to read chips removed from the board, it attaches to an unopened, unmodified phone over a standard external interface and extracts data over that.
- polar 5y agoCellebrite's "Physical Analyzer" can parse imported data, including disk images and chip images.
- PeterisP 5y agoIn that case it can't alter any evidence in an undetectable way - it can't alter the disk or chip itself; and it can't alter the image without changing the (already recorded offline) image hashes.
- sitkack 5y agoHow do you know that? If the imported data pops the host process, it could take over the host and mount the phone read/write.
- georgeplusplus 5y agoI understand that. My intent was to point out the difference between traditional digital forensics and what cellibrite does.