Decrypting the Signal App
cellebrite.com
cellebrite.com
> Decrypting messages and attachments sent with Signal has been all but impossible…until now.
> We found that acquiring the key requires reading a value from the shared preferences file and decrypting it using a key called “AndroidSecretKey”, which is saved by an android feature called “Keystore”.
Yeah, if you have all the keys you can decrypt stuff..
This is dumb, pleas please do not upvote
I expect the intended audience for this article is digital forensics examiners, who might be employed by say law enforcement or corporate investigators. Not the average Hacker News crowd.
Post-physical unlocked HD access to the device, aka digital forensics.
The much more interesting question is how they might extract keys from the Android Keystore (where key material is very often stored in a Secure Element or similar), but they don't even mention that this might be quite challenging - the article just ignores the question.
This is not newsworthy, there are normal tools that do similar things: https://github.com/xeals/signal-back
Ugh.
But to the average digital forensic examiner (working for police, lawyers, corporate investigators etc.) it means rather than having to use a separate tool (or asking a more technically qualified analyst to assist, or missing them altogether), Signal related artefacts are now processed and presented alongside everything else that Cellebrite PA supports (i.e. other built-in and third-party applications, media files, OS logs etc.). If they don't support Signal already, the dozens of other commercial and open-source forensic tools and their customers will benefit from this article soon, as will the poor folks responsible for maintaining quality standards in forensics labs (such as ISO 17025).
EDIT: Example of a Cellebrite competitor with similar a capability: https://blog.oxygen-forensic.com/115-2/ ("Oxygen Forensic® Detective enables extraction and decryption of encryption keys from the Android KeyStore on Android devices that are not using hw-backed keys in the encryption process.")
(Android devices use Full Disk Encryption by default and extracting this data needs an attacker that has gained access to unlocked storage first.)
The only way to secrets on a device with an HSM is to get past FDE, get root, and disable the HSM BEFORE the keys are created/stored.
Disabling the HSM after the keys have been stored simply wipes the keys and makes them unrecoverable forever.
Isn't that an oxymoron?
This sounded like just the process you’d use once you have the key, but getting the key is presumably the hardest part.
So, is Signal Secure?
Cellebrite doesn't have a way to extract secrets from an HSM for Signal or any other app. If the secrets aren't in an HSM, then they have this new feature to automatically take advantage of that.
So Signal is still secure. Just perhaps not on a $50 Cricket phone with no HSM. But then again, neither is anything else.
On some more expensive devices keys can be obtained from RAM[1].
[1] https://www.cellebrite.com/en/blog/decrypting-databases-usin...
More importantly, the app is already unlocked anyway if the keys are in RAM. So that just lets you keep it unlocked. It doesn't help you unlock an app that was locked when you got access to the device.
[1] https://www.msab.com/2018/12/11/msab-introduces-access-servi... [2] https://www.cellebrite.com/en/advanced-services/