Signal's CEO Just Hacked the Cops' Favorite Phone Cracking Tool
gizmodo.com
gizmodo.com
Love it.
I assume those images are going to be for the benefit of somebody looking at data extracted through Cellebrite?
As it stands, if law enforcement for some bizarre reason decide to examine my personal devices, there will be nothing on there of interest to them. If Signal start bundling exploits onto my device, that will no longer be the case. That's a potential risk to me, and Signal should be asking my permission before taking the risk.
Yes you have nothing to hide, but the police in many cases aren't honest. What if you live in the Middle east and are gay, you use signal, this protects you. Cellebrite are happy to sell their product to oppressive regeimes and if you are black the US police could be considered oppressors.
"Hey, your phone corrupted our 'lawful' intrusion system. That violates a long list of statutes. We're going to beat you with this wrench now, because you made our day worse, and then charge you with crimes against the state."
So now we are saying don't protect yourself because if you do that would imply you have something to hide,and are therefore guilty and deserving of the wrench beating.
It is a different game if Signal makes the sharding opt-in. If someone vacuums my phone and it turns out that my treatise about Little Bobby Tables [1] breaks the vacuum, that is fine by me.
If they make it opt-in then surely that is worse for the user. Then the oppressive regime can say "you deliberately did this thing".
I am outlining a hypothetical scenario where the authorities choose to look through my phone for ${UNRELATED_REASON}, and the presence of Signal's hypothetical exploit files would cause their digital forensics software to crash. In this hypothetical scenario, that crash in and of itself could then be taken as a reason to charge me. I don't believe "the app software maker selected my phone at random to have those files on it!" would help me out in that situation; that's the sort of nuance that tends to get completely lost.
The opt-out option would help me because, having opted out in advance, the hypothetical exploit files would not be on my phone.
I do agree that this is a slightly far-fetched scenario. However, I am very confused how HN can generally be of the opinion that having unwanted malware on your phone is a good thing, even if Signal put it there.
This fantasy that you can get away from a situation in which you are being interrogated and your phone is being searched by being compliant and proving your innocence to the nice police officers is extremely dangerous. Being compliant and providing information beyond what's legally required is the exact opposite of what you want to do, and preventing yourself from being charged should be the last thing on your mind. You should take it as a given that you will be charged.
edit: If you're outside the USA ignore this advice and listen to someone more local who knows their stuff.
Why would they make it crash the software though? There's no reason to do anything that's visible to the operator, perhaps it just alters data previously downloaded from other devices and then deletes itself. Or changes nothing other than adding a friendly file called moxie.says.hi.txt
1. We found a cellebrite kit that "dropped out from the back of a van" (yeah right lol)
2. Cellebrite is a tool to extract data out of phones (general intro to what Cellebrite is)
3. Looks like Cellebrite is using a bunch of open source libraries and they also use Apple DLLs (???!!!)
4. Oops looks like they are using like YEARS old libraries and there are hundreds of KNOWN vulnerabilities on each of those libraries.
5. Oops looks like the vulnerabilities allow ACE. Here's a demo where we placed a carefully crafted file with the ACE payload on a phone where if you just click the scan button on Cellebrite's software, you can do ACE (this is the video in the middle of the article)
6. (by the way for cellebrite users) this calls into question all data extracted with Cellebrite since these exploits are trivially exploitable. There are so many exploits possible so you can use any of them to create ACE attacks.
7. For COMPLETELY TOTALLY UNRELATED AESTHETIC REASONS we are putting some files on the Signal app. You're welcome!
---
to spell it out: yes, they are putting ACE payloads on Signal to try to crash investigators/spies/whatever trying to use Cellebrite on phones with the Signal app.
7 is actually a lot more subtle, I didn't get it at first. They're putting some files on some signal phones, somewhat randomly, and only those which seem like they've been in active normal use since before this disclosure. So likely none of the devices Cellbrite might own for testing, and no device Cellbrite might buy in the future, but some random set of existing devices in the field. And there might be multiple such files, so even if Cellbrite find one they can't be sure they've got them all.
Now assume these files are (as somewhat implied) exploits that cause the falsification of data in all current and future reports issued by a given Cellbrite device.
That means that if a Cellbrite has, after this point, ever scanned a phone with Signal installed it might be issuing false reports.
THAT means that there's a reasonable doubt in any evidence obtained by the use of a Cellbrite device, going forward. That gives an easy out to defense attorneys in the US, where Cellbrite devices are used by police to gather evidence.
Any defense attorney can now argue that evidence obtained from a Cellbrite shouldn't be admitted in court, since they don't maintain forensic integrity. This essentially spoils Cellbrite's entire business in the US (and any other country with similar standards for the admissibility of evidence).
So Cellbrite has to find ALL the exploits in their system, and be very, very sure they've not missed any. Because defense attorneys will then try to call that into doubt. Etc.
Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer - https://news.ycombinator.com/item?id=26891811 - April 2021 (293 comments and counting)
While not judging a book by the cover, this cover was definitely more attractive to my atention span.
We downweight follow-ups that don't contain significant new information: https://hn.algolia.com/?dateRange=all&page=0&prefix=true&sor... and https://hn.algolia.com/?dateRange=all&page=0&prefix=false&so...
Repetition is not good for curiosity: https://hn.algolia.com/?dateRange=all&page=0&prefix=false&so...
Front page is the scarcest resource: https://hn.algolia.com/?dateRange=all&page=0&prefix=true&que...
... and no doubt a bunch of others.
Do you think Signal is the first or only one to set traps for Cellebrite?
if a state agent is worried about this kind of thing they just carry a clean device, and for most of them if they are ever in a situation where their device is inspected, the game is already over.
(I don't think the above summarization alters the intent of your statement.)
IMO, if you're at "state agent" level, well, just about all the countries either have the manufacturing capacity, either locally or through agency partnership with ally countries, to construct devices capable of maintaining a clean the appearance even while being examined with very expensive equipment.
For example, you could probably do a lot if you could replace the 0th-stage bootloader in the NAND controller. And NAND is manufactured at such crazy scale, the one-off test runs probably wouldn't be all that expensive, and the turnaround time might even be weeks to days.
it's widely used by phone-shop- and carrier service staff to migrate data.
> ...One way to think about Cellebrite’s products is that if someone is physically holding your unlocked device in their hands, they could open whatever apps they would like and take screenshots of everything in them to save and go over later. Cellebrite essentially automates that process for someone holding your device in their hands.
It's very carefully worded ("One way...") to not exclude unlocking without password, though. Perhaps Cellebrite also has password guessing capability?
[1] https://www.wired.com/story/cellebrite-ufed-ios-12-iphone-ha...
While this report is entertaining to read, I have to wonder about possible downstream repercussions of the implications within the last paragraph; if you're in police custody or worse and your Signal app contains some 'aesthetically pleasing files' that interfere with the authoritarian software, it's likely going to be your ass on the line for all sorts of charges.
Don't get me wrong, the implication is enough to discredit Cellebrite, but my initial thoughts are that either this bluff gets called, or there's a non-zero risk of someone landing in even hotter water down for using Signal. Of course, this assumes that you're not already neck-deep for having encrypted data and upholding your right to privacy.
If you live in a country with the rule of law, then just using an app doesn't make you guilty of anything. The fact the this security feature has been publicly declared puts the onus on cellebrite and the police using their devices, to ensure relevant patches are applied at their end to prevent these features from working. These devices are already bypassing android and iOS security features to do what they do, this is no different.
To me these files are essentially similar to a passcode on a device.
I'd say if Signal wanted to have an impact then silently adding support that breaks cellebrite would be more effective.
She's due for a new phone soon, and the cell companies use Cellebrite to transfer data from one phone to another.
She will almost certainly want them to do it as I'm not there to help her in person.
What happens when Signal shards to her device and uses it as a weapon against the machine and her phone is bricked or she's liable for the machine's costs or our entire history is deleted or something just as destructive?
Please don't force your threat model down our throats. Your hacktivism is not my hacktivism. This shit better be opt-in.
This is incredibly unethical.
Did you read the text at the bottom of the post? They are randomly installing malware on users' devices to break or harm or otherwise self-destruct when Cellebrite machines read them.
I'm not speaking for myself. I would opt in personally. I'm speaking for my mother who just wants a secure and reliable line of communication with her son without being pulled into some offensive scheme that could land HER in trouble or cause damages.
If something is broken or destroyed without user knowledge or understanding or consent, you better believe Signal will see court cases.
It's entirely possible that I'm wrong and this will cause your phone to explode, but if you don't trust the Signal developers enough to assume they won't intentionally explode your phone, you probably shouldn't be using their product.
Signal is providing a strong, albeit rude (likely in response to Cellebrite's claims), incentive to fix their shit. Would you rather have a temporary period where transfers weren't working, or deal with the scenario above in a year?
If that were the case, fine. But the post does not specify the effect of the "aesthetically pleasing" files. They could destroy all Signal data or irreversibly harm the machine itself.
We just have to "trust" the Signal devs to not do that?
This is not how security should work.
You're trusting the Signal devs to your keep messages safe and secure. I don't know if that means wiping all messages when accessed via Cellebrite, but that seems like a reasonable option. My assumption would be that they will just crash or brick the Cellebrite software. Either way and completely independently of the aesthetically pleasing files, if you disagree with the choices Signal makes to keep your messages safe and secure, there are many other messaging options that you can use.
Publicly calling out big security problems is exactly how security should work (notwithstanding specifics of disclosure).
That's the problem. The fact nobody sees the effects of this is absolutely surreal and alarming.
If you don't know how to pay your taxes, you're still required to pay your taxes.
Their intention is to render using Cellebrite for court evidence worthless by suggesting that the record could have been tampered with at any point, if any phone the user scanned had Signal on it.
Proving that no phones ever had an 'aesthetic' file that could cause damage to Cellebrite is impossible, and they've provided clear reason why it is impossible to prove.
I don't think Signal will do that though, if it does, it will most likely get kicked out of every store and the company will most likely end up in well-deserved legal trouble, as if MOB wasn't shady enough...
As someone else said, it is more likely to be a way to discredit evidence extracted by Cellebrite.
The millions of users like me who do nothing sensitive with it add bulk to traffic, making it harder to single out "interesting" data. I mean, for example, if only criminals used Signal, just having the app will get you a lot of attention from the police, as it happened with Encrochat.
As it stands, Signal is more of a threat to her well being than anything else.
Not a single mention of carrier or consumer tools, but lots about analyzing your data.
I guess your cell phone company feeds every cell phone they work on to some centralized data repository (out of jurisdiction of your current locale) to be analyzed is what sounds like is going on.
These machines are still used for this purpose. I don't doubt they're also used for surveillance or tracking. But they're not only used for that.
You're speculating as to what the phone companies do with the machines, especially given that it would be incredibly illegal to do so and trivial to whistleblow and thus a huge risk to the companies to do this on a widespread basis. Please provide proof instead of contributing to hysteria.
You chose to get into a captive ecosystem; Signal's code-dump "look but don't touch" (well, clientside, serverside was closed source for a year). Signal's "our way or the highway".
As impressive as the hack looks, we are putting trust in Signal that it’s real since they didn’t disclose the vulnerability and no one else has reproduced it. It could just be a clever attempt at socially engineering the public opinion of Cellebrite.
I posted a more detailed analysis on the original story: https://news.ycombinator.com/item?id=26898638
Public opinion of Cellebrite was already extremely low.
If so, that sounds potentially libelous (IANAL).
"There's nothing to see here, folks!"
Honestly, i would be very surprised if cellebrite didn't have massive vulns. Its the type of software that always does.
> As just one example (unrelated to what follows), their software bundles FFmpeg DLLs that were built in 2012 and have not been updated since then.
This purported vulnerability is not related to FFmpeg in any way, hence the disclaimer.