6 ms·
I would guess that it is way simpler than that. What will be gauged is the intent. This file is targetted to damage LE property, it is hard to argue that they
by gbin 5y ago
I would guess that it is way simpler than that. What will be gauged is the intent.
This file is targetted to damage LE property, it is hard to argue that they are random bytes.
- toomuchtodo 5y agoThe intent is to protect the content of the user’s device from unauthorized access by poorly written forensic extraction code. It’s not offensive but defensive, as Cellebrite has to actively read the file, a file which is not theirs. Technically, Signal owns the copyright and does not authorize Cellebrite to read it (I’d assume, legally).
- alisonkisk 5y agoCopyright does not prevent lawful seizure of material.
- deleted 5y ago[deleted]
- toomuchtodo 5y agoSignal payloads don’t prevent competent, properly implemented seizure and forensic analysis.
- count 5y agoAnd technically if the LEO user of Cellebrite has a warrant, they are legally authorized to look at that data no matter what Signal or the phone's owner thinks. So, in that sense, it's the ultimate 'authorized access'.
- toomuchtodo 5y agoYes, I agree LEO with authorization to seize and search someone’s property (with a warrant or similar due process) is authorized to utilize a forensics tool chain that adheres to application security best practices (without which taints chain of custody). None of my comments should be construed as supporting the evasion of a legal law enforcement act. I take issue with LEO overreach when it occurs and vendors shoveling garbage (paid for with tax dollars) to the justice system.
- jakelazaroff 5y agoIANAL but I’m pretty sure that’s not how it works. A judge won’t throw out evidence just because a tool doesn’t “adhere to application security best practices”. They’ll need to be convinced that the specific evidence they’re reviewing is compromised or unreliable.
- toomuchtodo 5y agoAgreed! I’d like to see it tested in court. Tools used in the justice process must be held in the highest regard considering someone’s freedom hangs in the balance. The courts forced a breathalyzer manufacturer to release their source code, so there is precedent for critical review of such tools. https://nccriminallaw.sog.unc.edu/breathalyzer-source-code/ https://nccriminallaw.sog.unc.edu/breathalyzer-source-code/
- jakelazaroff 5y agoI would like to see that as well. But I think that sidesteps what I’m saying, which is that it’s probably not sufficient to show that the tool used to gather evidence might, under certain circumstances, be susceptible to malicious interference.
- salawat 5y agoNope. As soon as one case has reasonable doubt introduced, it's precedent. Now judges will balk at backpropagating it to previous cases before the exploit possibility was made public knowledge; however, one could make the case a recheck effort should be initiated, because in the grand scheme of things, Moxie is technocally a disinterested party. Those who have direct stake may have been keeping this potential capability in their back pocket for strategic use.
- jakelazaroff 5y agoWell, we won’t know until this actually gets tested in court. But frankly, I’m putting my money on the analysis from the Stanford lawyer with subject matter expertise, not random armchair lawyers on HN.
- simfree 5y agoCellebrite sells their hardware to lots of non-LEO, including corporate security, law firms, private investigators and regimes that have no respect for human rights. Cellebrite's UFED hardware even shows up on eBay and other online sales platforms. If someone has a Cellebrite, they do not necessarily have a lawful right to access. Could just be a $16/hr Pinkerton (a wholly owned subsidiary of Securitas) using UFED on a phone they stole from an employee or contractor of the organization they contract with.
- dTal 5y agoI feel like this is a key point for the entire discussion. The legality of deliberately foiling lawful investigations is debatable, but protecting yourself against wild-west malware decidedly less so. That being said - if it's all fine and dandy, I don't see why a Cellebrite-foiler couldn't be a separate app. Moxie (threatening to) piggy-back it onto Signal, purely because it's the app he controls, is a deeply user-hostile move.
- dylan604 5y ago> Cellebrite's UFED hardware even shows up on eBay and other online sales platforms. I'm surprised Cellebrite allows for this. I would have assumed that the sales contract would include a "this is a lease, not a purchase" type of wording so that "you may not sale this device to anyone" with a buy back clause provided instead.
- WrtCdEvrydy 5y agoYou'd be surprised but older generation UFEDs end up on eBay for under $1000 often. I have one at home but yeah, there's no EULA preventing you from selling something that's yours.
- dylan604 5y agoI'm not surprised that it is happening at all. Of course someone that paid a large sum of money for something that they no longer need/want will result in them trying to sell it to recoup some money. My surprise is that Cellebrite does not buy them back to keep the demand/supply artificial.
- iforgotpassword 5y agoBut are you obliged to consent? Do you have to give them all your passwords too? Can they use "data exfiltration tools" on humans? If the focus of your exploit payload is specifically to neutralize the attack and not cause extended or arbitrary damage, could this be counted as "self defense" or just protecting your privacy?
- salawat 5y agoNow you're asking the important questions. We're getting to a point where we have so much of our personal memory, effects, and essence on our phones that there is no reasonable substitute to seperate the data on our devices as being seperate from our mind. That implies 5th Amendment should apply to electronic testimony, which will be fought tooth and nail against by the judiciary. This will have to be tested sooner rather than later as we get closer to realistic and functional Brain/computer interfaces.
- PeterisP 5y agoYes, you're obliged to consent - you don't necessarily have to help them, but you're also prohibited to obstruct or delay them, especially destroy or hide the evidence. A lawful warrant overrides any expectations of privacy. Furthermore, there's no "self-defence" concept in any computer-related statutes; protecting a life can be an excuse for certain otherwise illegal actions, but protecting your data or devices is not; a "hack-back" is a crime on its own even if it would run on a criminal's computer, but in the Cellebrite case it's presumed that when law enforcement runs the data collection, they have full legal rights to access that device and data. For a physical world analogy, let's suppose that someone gets shot, and you run away with the gun used and throw it into a river. Even if you'd be acquitted for the shooting itself (due to e.g. self-defence, or perhaps someone else did that shooting), you can be convicted for throwing the gun into the river as tampering with physical evidence, as hiding that gun is a crime by itself if the jury assumes that you did it so that it wouldn't get used as evidence. That applies even if there wasn't any warrant yet, as the investigation hadn't yet started; it's sufficient that you would have expected that this might get used as evidence.
- alexeldeib 5y ago
- feanaro 5y agoSure, but the LEO has to ensure that their tools are not broken. This is not anyone's responsibility but theirs.
- ArnoVW 5y agoThis could have been a potential line of reasoning, if they would have implemented it, and if Signal were taken to court for it. The problem is, they wrote this article. Where they say they will put 'aesthetically pleasing' code on installations. But not all installations. So Cellebrite can claim it's a menace (sort of a booby-trap) , and not a protection (sort of a shield). Another issue: they say they obtained then kit because it fell of a truck. Any judge knows that 'fell of a truck' is a manner of speaking. Thanks to their statement it will be possible for Cellebrite to say "We checked the last 6 months of deliveries, no truck incidents". Cellebrite can try to find civil statutes (fraud?) and ask for discovery. If that is allowed by the judge, Signal will have to show all documents and messages pertaining to the hack, or risk contempt of court or perjury. This is what the article is about. TL;DR: great work guys, wish you had consulted a lawyer before writing the post though.
- knaik94 5y agoCellebrite is not law enforcement property, I'm sure the copyright and code is still owned by Cellebrite. Additionally Cellebrite sells their tools to more than just LE.
- anaerobicover 5y agoJust so Linux is not copyright to me, but to introduce my computer to malware is crime against my property, not Linux Foundation.
- batch12 5y agoThe file doesn't have to damage anything owned by LE/private companies. It could protect files on the device from unauthorized tampering by wiping or encrypting files when it's executed.
- simfree 5y agoCellebrite sells their hardware to corporate security, law firms, private investigators and despotic regimes and their UFED hardware even shows up on eBay and other platforms for the general public to buy at times. LEOs are far from the only buyers of this hardware, a good chunk of Cellebrites userbase operate extrajudically and do not have a lawful right to attempt to access the contents of phones they use UFED on.
- unyttigfjelltol 5y ago+1. Signal was in exceptional territory with it's release, but we've seen an increasing acceptance among sophisticated legal minds of hacking hackers. The blog's analysis was pretty half-baked to me.