Helping law enforcement lawfully access the Signal app
cellebrite.com
cellebrite.com
I'll quote the top post from there.
> This immediately smells of marketing bullshit:
>> Decrypting messages and attachments sent with Signal has been all but impossible…until now.
>> We found that acquiring the key requires reading a value from the shared preferences file and decrypting it using a key called “AndroidSecretKey”, which is saved by an android feature called “Keystore”.
>Yeah, if you have all the keys you can decrypt stuff..
> This is dumb, please please do not upvote
Does signal allow generation of new passphrase protected private key and can this software bypass that?
Post-physical unlocked HD access to the device, aka digital forensics, is assumedq here, this is what this company does.
As others have pointed out Signal might have been storing the local pin/password in an Android secure enclave of "AndroidSecretKey" which they found other means around.
https://web.archive.org/web/20201210150311/https://www.celle...
If you can't tell for yourself, here is Moxie's reply (also linked to by the same hn user):
> This (was!) an article about "advanced techniques" Cellebrite uses to decode a Signal message db... on an unlocked Android device! They could have also just opened the app to look at the messages.
> The whole article read like amateur hour, which is I assume why they removed it.
> https://twitter.com/moxie/status/1337434126186553345
--
Basically yeah, adding a pin to signal would also prevent this, they didn't bypass such extra measures.
This is what they did in their blog post:
> We found that acquiring the key requires reading a value from the shared preferences file and decrypting it using a key called “AndroidSecretKey”, which is saved by an android feature called “Keystore”.
No further mention of it, so I assume they just had access to it. From Moxie's post, I assume that the keystore is unlocked when the phone is.
How can they say that? After they sell the device they won't know how it will be used.
Just guessing, and trying to be charitable.
Is it possible for something to be open-source and proprietary at the same time? Is it possible if one assumes the definition of the OSI?
I don't buy it. Can you find any instances where it's used like that? According to that definition, you could also say "SpiderMonkey is Mozilla's proprietary javascript engine", which is obviously absurd.
Furthermore, the definitions listed on wiktionary and merriam-webster both seem to incorporate some sort of exclusivity. Just because it's your own variation doesn't make it proprietary.
Here it's a case of semantics, whether you're talking about the open-source software or the full package including services from Mozilla and the Firefox branding. Firefox as a whole is certainly proprietary to Mozilla, even if the code is not.
I suspect the intent re: signal is similar, where the code is indeed open-source, but IIRC signal doesn't network with non-official clients?
Probably best to avoid using the word "proprietary" because of the confusion/connotations, but I don't think it's entirely wrong.
It is not. Although in this case, it could perhaps be interpreted as "proprietary protocol for (interacting with?) open-source encryption".