Israeli firm can steal phone data in seconds
phys.org
phys.org
Am I to believe that this firm is the right hands? Or government? Please...all hands are the wrong hands. These vulnerabilities need to be closed. I wouldn't be surprised if the NSA or some other government tentacle was paying them not to make whatever they found known.
Gee, I sound paranoid. What am I thinking, our government would never do that. Oh wait... http://www.reuters.com/article/us-usa-security-rsa-idUSBRE9B...
It looks like your are unsure, so let me clarify.
There really are companies whose only business is to find and sell vulnerabilities to states. (Whether it's exclusive is just a matter of negotiations).
"You can't blame the car manufacturer at that point for delivering a car that was utilised to commit that kind of crime," he said.
This is specious reasoning. The point of a car is not to run over people; it's to go from point A to point B. This technology, on the other hand, has only one purpose: to break into cellphones.
Just following orders and the local laws...
He's saying (if I understand correctly, it's awkwardly phrased) that his company sells only to a small number of clients who are all regimes (meaning states). There are only a handful so he can vet them and demand commitments that the technology will only be used for good.
Plenty of other reasons to disagree. But, he is basically agreeing with you that this technology should be treated as a dangerous weapons-like thing and controlled in the way the sale of advanced weapons is controlled.
Our problems stem from overfunded and underregulated intelligence agencies, not from the tools they use.
The same principle applies to gun rights for example. The gun itself isn't the problem, it's how someone chooses to use it. (self defense vs crime). Nobody is an absolutist here, everyone draws the line somewhere slightly different.
Outlawing the tech ensures that good guys lose the arms race every time.
When I say good guys I don't necessarily mean the government. I mean anyone out there who is not using the tech for malicious intent. People using guns for self defense, breaking into an encrypted device to solve a crime, or retrieve lost work etc.
This keeps the focus on improving the actual technology (encryption). Rather than just banning law abiding citizens from taking part.
"The bumpy road towards iPhone 5c NAND mirroring" - https://arxiv.org/abs/1609.04327
And the video:
Fingerprint unlock can save you some of the PITA of typing it - just be sure you power off your device when you have even the slightest chance of encountering an actor that could seize your mobile device - that way the passphrase will be required.
Unless, of course, the data in it's final state before the final factory reset is un-encrypted.
I would say if you have data on your smartphone you don't want recoverable at rest, take module0000's advice, then also use encryption, and then also use a multi-pass wipe tool on particluar files. Of course all of this could still not work.
For example, I'm not sure what the forensic ramifications of a seemingly more complex filesystem like APFS will be in the near future when it hits iOS.
[1] https://bits-please.blogspot.com/2016/06/extracting-qualcomm...
Just like security itself - the goal is to provide enough barriers so predators go looking elsewhere for easier prey.
That doesn't really restrict the NSA, CIA, FBI or any other agency/PD from buying their services. After all, that's what "black budgets" are for.
All this assuming they even care about legal compliance, which I am sure that under the correct circumstances it won't matter one bit.
Israel is also a member of the WTO so there is that avenue also.
Do not purchase a phone from a vendor that engages in this unethical practise.
Cellebrite gets early access to phones NOT due to its forensics operations, but for UME, since carriers (and that's lots(!) of carriers worldwide) are very much interested in good consumer experience on the devices' launch day.
I actually doubt it's been particularly significant to its forensics operations.
The article seems to paint it as a "we're confident we could" - which seems bizarrely vague. Why would they do that when they claim they can crack an LG G4 wide open?
> Ben-Peretz remains confident his company can crack even the newest iPhones.
> iOS devices have strong security mechanisms that give us a challenge, but if anyone can address this challenge and provide a solution to law enforcement, it is Cellebrite," he said, referring to Apple's operating system.
This makes it sounds like Cellebrite actually cannot currently crack the latest phones running iOS 10, but the CEO is merely expressing his belief that they'll figure out how to do it. See how he's not saying "we can do it", but instead he's saying "if anyone can do it, it's going to be us".
They might be able to do what they claim, but not much was actually presented.
It's not like there's a shortage of relevant skills in the US (supposedly responsible for stuxnet) or Russia.
Or is it just that <scary government agency> doesn't want to share its toys with <local police>?
Dunno about the situation with other phones but given that many cheap Androids run Mediatek, it's not very difficult to claim a huge number of "crackable phones".
The only thing that should protect you from any kind of government snoops is encrypting your phone with a strong passphrase and shutting it off once you leave a room taking the cops less than 30 seconds to enter.
Does encryption defeat this when the device is off? If not what flaws exist in the encryption schemes?
All that being said, Israel is also known as being just as active if not moreso than Russia and China in their espionage against the US. I think that's also worth considering.
Among all the claims this one seems like it might be one that holds up with very recent iOS/Android releases. It would be interesting to find out whether they rely solely on the encryption to protect the deleted messages and whether overwriting the data would be thwarted by flash device wear-leveling indirection.
They didn't settle for good enough.
They didn't weasel out of it by blaming "ease of use" concerns.
They didn't argue that maximum security wasn't a high priority for their customers.
They didn't deploy marketing slogans to pretend like they had done the hard engineering work. (cough Knox cough)
E.g random article from bestbuy.
http://www.bestbuy.com/site/at-t-gophone-lg-b470-prepaid-cel...
My own password is a random 16 character string.
An app on F-droid known as "Cryptfs Password" can change the encryption password separately from your screen unlock password. It also bypasses the 16 character limit, as the encryption key I used on my last phone was 27 characters. At the end of the day Android encryption runs using dm-crypt, so the same sort of rules apply. The 16 character limit is a UI limitation, and there's no technical reason for it.
* Note: I fully acknowledge that Google needs to do better here, as I would never assume a normal user could root + install Cryptfs password + unroot after, but at least for those of us who can, we can do something in the meantime.
The same kind of boneheaded removal of features in the name of simplicity is behind Android Pay requiring your phone to have a locked screen -- because that supposedly solves the problem that used to exist of users having to enter a PIN twice when they'd unlock the screen and then unlock Android Pay.
Take Trump's mouth blast with a grain of salt, as its not what he will end up doing once he learns what he is talking about.