8 ms·
And technically if the LEO user of Cellebrite has a warrant, they are legally authorized to look at that data no matter what Signal or the phone's owner thinks.
by count 5y ago
And technically if the LEO user of Cellebrite has a warrant, they are legally authorized to look at that data no matter what Signal or the phone's owner thinks. So, in that sense, it's the ultimate 'authorized access'.
- toomuchtodo 5y agoYes, I agree LEO with authorization to seize and search someone’s property (with a warrant or similar due process) is authorized to utilize a forensics tool chain that adheres to application security best practices (without which taints chain of custody). None of my comments should be construed as supporting the evasion of a legal law enforcement act. I take issue with LEO overreach when it occurs and vendors shoveling garbage (paid for with tax dollars) to the justice system.
- jakelazaroff 5y agoIANAL but I’m pretty sure that’s not how it works. A judge won’t throw out evidence just because a tool doesn’t “adhere to application security best practices”. They’ll need to be convinced that the specific evidence they’re reviewing is compromised or unreliable.
- toomuchtodo 5y agoAgreed! I’d like to see it tested in court. Tools used in the justice process must be held in the highest regard considering someone’s freedom hangs in the balance. The courts forced a breathalyzer manufacturer to release their source code, so there is precedent for critical review of such tools. https://nccriminallaw.sog.unc.edu/breathalyzer-source-code/ https://nccriminallaw.sog.unc.edu/breathalyzer-source-code/
- jakelazaroff 5y agoI would like to see that as well. But I think that sidesteps what I’m saying, which is that it’s probably not sufficient to show that the tool used to gather evidence might, under certain circumstances, be susceptible to malicious interference.
- salawat 5y agoNope. As soon as one case has reasonable doubt introduced, it's precedent. Now judges will balk at backpropagating it to previous cases before the exploit possibility was made public knowledge; however, one could make the case a recheck effort should be initiated, because in the grand scheme of things, Moxie is technocally a disinterested party. Those who have direct stake may have been keeping this potential capability in their back pocket for strategic use.
- jakelazaroff 5y agoWell, we won’t know until this actually gets tested in court. But frankly, I’m putting my money on the analysis from the Stanford lawyer with subject matter expertise, not random armchair lawyers on HN.
- strogonoff 5y ago> A judge won’t throw out evidence just because a tool doesn’t “adhere to application security best practices”. They’ll need to be convinced that the specific evidence they’re reviewing is compromised or unreliable. If the tool doesn’t “adhere to application security best practices” then the evidence is compromised and unreliable. Take a wild guess at how many states and other well-funded actors have been quietly deploying their anti-Cellebrite defences in the wild until Signal has made theirs public. If Signal was able to obtain Cellebrite, what is the chance they weren’t?
- deleted 5y ago[deleted]
- Beldin 5y agoMaybe in the USA. In Europe, evidence in criminal court cases needs to adhere to standards such as chain of custody. Which Cellebrite obviously fails given this research - their tool's output could be manipulated.
- jakelazaroff 5y agoAnd someone could have opened an evidence bag and resealed it, but my guess is you don’t see courts throwing out evidence unless there’s reason to believe that actually happened.
- salawat 5y agoThere is, in fact, a current court case around a Sheriff's deputy accused of planting methamphetamine related paraphenelia in over 162 cases. See the ongoing Zachary Wester affair. That's falsely implicating 162 innocents of a felonius crime, tarnishing their future prospects for life, which reulted in plea bargains being accepted because the accused could not get sufficient legal representation to make the prospect of a successful legal defense doable, and a completely innocent of the charge individual didn't want to run the risk of amplification of sentence just for exercising a civil right. Besides being an example of why plea bargains make a mockery of our legal system; "just take this lesser charge that we don't have to really work at proving it so we can be done with it, because think of how bad the sentence will be if you make us work at it", it demonstrates that even procedures as they are now are such that an officer/prosecutor have and are willing to exploit their capability to manufacture suffering for those they serve for personal gain. The System is getting shocked by it's vulnerability to the untrustworthy agent currently. So I wouldn't discount some fundamental reassessments of procedure down the road.
- acdha 5y agoIt is a travesty but I think that case works more for the person you’re replying to: it was evidence of misconduct (the prosecutor noticing his body cam footage didn’t match his reports) which called that into question, not just saying someone _could_ have tampered with the evidence. This will work the same way: if there’s corroborating evidence, it’s likely to be as futile as the original article’s author predicts, but if there is something speculative which has only unconfirmed evidence from Cellebrite it might be enough to get that thrown out.
- simfree 5y agoCellebrite sells their hardware to lots of non-LEO, including corporate security, law firms, private investigators and regimes that have no respect for human rights. Cellebrite's UFED hardware even shows up on eBay and other online sales platforms. If someone has a Cellebrite, they do not necessarily have a lawful right to access. Could just be a $16/hr Pinkerton (a wholly owned subsidiary of Securitas) using UFED on a phone they stole from an employee or contractor of the organization they contract with.
- dTal 5y agoI feel like this is a key point for the entire discussion. The legality of deliberately foiling lawful investigations is debatable, but protecting yourself against wild-west malware decidedly less so. That being said - if it's all fine and dandy, I don't see why a Cellebrite-foiler couldn't be a separate app. Moxie (threatening to) piggy-back it onto Signal, purely because it's the app he controls, is a deeply user-hostile move.
- dylan604 5y ago> Cellebrite's UFED hardware even shows up on eBay and other online sales platforms. I'm surprised Cellebrite allows for this. I would have assumed that the sales contract would include a "this is a lease, not a purchase" type of wording so that "you may not sale this device to anyone" with a buy back clause provided instead.
- WrtCdEvrydy 5y agoYou'd be surprised but older generation UFEDs end up on eBay for under $1000 often. I have one at home but yeah, there's no EULA preventing you from selling something that's yours.
- dylan604 5y agoI'm not surprised that it is happening at all. Of course someone that paid a large sum of money for something that they no longer need/want will result in them trying to sell it to recoup some money. My surprise is that Cellebrite does not buy them back to keep the demand/supply artificial.
- iforgotpassword 5y agoBut are you obliged to consent? Do you have to give them all your passwords too? Can they use "data exfiltration tools" on humans? If the focus of your exploit payload is specifically to neutralize the attack and not cause extended or arbitrary damage, could this be counted as "self defense" or just protecting your privacy?
- salawat 5y agoNow you're asking the important questions. We're getting to a point where we have so much of our personal memory, effects, and essence on our phones that there is no reasonable substitute to seperate the data on our devices as being seperate from our mind. That implies 5th Amendment should apply to electronic testimony, which will be fought tooth and nail against by the judiciary. This will have to be tested sooner rather than later as we get closer to realistic and functional Brain/computer interfaces.
- PeterisP 5y agoYes, you're obliged to consent - you don't necessarily have to help them, but you're also prohibited to obstruct or delay them, especially destroy or hide the evidence. A lawful warrant overrides any expectations of privacy. Furthermore, there's no "self-defence" concept in any computer-related statutes; protecting a life can be an excuse for certain otherwise illegal actions, but protecting your data or devices is not; a "hack-back" is a crime on its own even if it would run on a criminal's computer, but in the Cellebrite case it's presumed that when law enforcement runs the data collection, they have full legal rights to access that device and data. For a physical world analogy, let's suppose that someone gets shot, and you run away with the gun used and throw it into a river. Even if you'd be acquitted for the shooting itself (due to e.g. self-defence, or perhaps someone else did that shooting), you can be convicted for throwing the gun into the river as tampering with physical evidence, as hiding that gun is a crime by itself if the jury assumes that you did it so that it wouldn't get used as evidence. That applies even if there wasn't any warrant yet, as the investigation hadn't yet started; it's sufficient that you would have expected that this might get used as evidence.
- alexeldeib 5y ago
- feanaro 5y agoSure, but the LEO has to ensure that their tools are not broken. This is not anyone's responsibility but theirs.