Reliability of police mobile phone evidence questioned after hack
theferret.scot
theferret.scot
Blog post from moxie: https://signal.org/blog/cellebrite-vulnerabilities/
https://twitter.com/mtmdlawyer/status/1386733853298069505
(imho) sobering thoughts on this to consider: https://twitter.com/meganmcgraham/status/1385328533711450114
But these type of vulnerabilities present a problem, in that reading the device could/would modify timestaps of the data captured. The solution is to not use Cellebrite, there are lots of forensic analysis tools. To be effective Signal would need to exploit the major vendors equally.
Edit - For the uninitiated: https://www.geeksforgeeks.org/write-blockers-an-introduction...
For mobile forensics, it's actually done through the built-in backup systems included in each of the major OS providers (Android/iOS).
This is a back and forth that has been ongoing since we began moving away from Hard Disks, as SSDs tend to manage their own internal state so an image of "an SSD" can change even if the underlying media hasn't changed as the SSD cell balancing can actually shift around deleted data or delay to clear certain cells.
If you'd like to know about the current issues around mobile device acquisition, you can check this out (https://ieeexplore.ieee.org/document/9116458) which contains the last paper I wrote on the latest issues on iOS and Android acquisitions.
Although I'd love to blame the big bad Cellebrite and the big bad police departments for junk science, computer forensics is quick to dismiss scientifically unsound items so I would expect a response from Cellebrite soon.
You are correct that the source system would not be modified. But the content you are presenting and analyzing via Cellebrite would.
If the phone could have been altered to add data before a forensic image was acquired in a way that looks like it was via normal use (reasonable timestamps, browser logs, etc.) then we'd have a real problem. Cellebrite potentially being used to do this as it reads the image is not that problem.
So most of these suites really just automate the backup extraction process and the automated analysis piece.
In the real world, you don't interface down at the USB interface other than just to kick off a backup (think an iTunes or adb backup) of the device and just grab it via USB then extract it on your computer and analyze it.
Maybe they could, and that would be the problem. Cellebrite's case now raises the issue of what will happen to those decisions where Cellebrite's products were used. This can void those court decisions retroactively, which could also happen to any major vendor in the next couple of years.
In any case, I doubt that this will make them stop using their products.
I bet they could. Any industry that's shrouded in secrecy tend not to have the sort of incentives that would ensure better security practices.
Isn't the point that the people operating the software and collecting the evidence are the ones that are supposed to safeguard it against tampering?
Is there any type of evidence that could stand up if we no longer trust the people handling it?
For me, this story isn't about fear that police could leverage the bugs to manipulate a case. It's about the constant fear that laymen rely on unverified "experts" to put people behind bars for years.
I think investigative corruption is a pretty good analogy.
The vulnerability allows any device plugged in to the "kiosk" with a malicious file to do anything it wants to any existing report on the "kiosk" as well as plant code for future execution in order to do anything else it wants.
Let's assume the device which does this does so silently, at what point are the police or Cellebrite supposed to know nothing in the kiosk can be relied on, ever?
With a piece of paper on the other hand, the other sheets in the folder don't suddenly rot when you add a maliciois sheet of paper, although this does sound like an interesting and potentially novel attack vector.
It is not clear from the article that analyzing a phone with malicious files will trigger the issue, unbeknownst to the operator. (E.g. it says "it is possible to execute code that...", etc.) However, I'll take your word for it and assume it was poor reporting in this case.
That does change things, thanks for the clarification.
Clearly we are entering a time of Low Trust Society, and the institutions have only themselves to blame as they have abused the populations trust for decades only now with free flow of information are regular people able to directly see the abuse that has existed for a very very long time.
We used to have a High Trust society, not because the people in power were trust worthy but because the people in power directly controlled the information.
This is no longer the case, and as that power is shifting we are now seeing the people that control information today looking for ways to retain that control and instead of allowing it to flow freely inject their own filters into the streams.
we're returning to a high trust society out of necessity because of economic forces that incentivize information asymmetry.
It's pointless to steal someone's car in a town of 30 families. everyone would know exactly where it went. You also know exactly who you are doing harm to so your sense of sympathy kicks in making you less likely to do it.
These tight knit low population towns seem to naturally create a high-trust honor culture. Small towns have a higher level of social integration so wronging someone creates repercussions that flow back to the perpetrator through every one of their social bonds.
Some places are higher trust than others but the developed world is based exclusively on a high level of trust. An actual low trust society is so starkly different from what most of us on HN are used: it practically enforces a feudal, subsistence farming society.
Living in the US, I don't remember the last time I had to show my receipt at the fast food counter or show any sort of identification when picking up food that I had paid for online. I've never once paid for a major/emergency medical operation or auto repair ahead of time. Hell, I left the dealership with my last car a full week before they received the check from my bank (in the Seattle area, so definitely not a small town). I don't think anyone has ever really verified my income or finances beyond a cursory credit check and some PDF that could be easily faked by anyone with a little computer literacy. Most mortgages are paid back over thirty years! In my old country, most people don't fully trust that the currency will even last that long.
The systems reinforcing social behavior in larger groups are more complicated and easier to game, but they are definitely still part of a system based on high levels of trust.
People only pay attention when things are happening at a scale they consider worthy of their attention. The reason corruption is less common at the higher levels is that people are focused on higher level officials; meanwhile, the fact that their local officials are breaking this rule or that rule goes unnoticed, unreported, or worse, happens with everyone's full knowledge and just gets shrugged off.
Also you mention a county tax collector. I wouldn't consider that a tight knit small town. I think there is a lot more corruption at a county level than a small town (from what I've seen).
I sort of get your point about more eyes watching someone the higher they go. Some of it is also the position of those watchers and their opportunities. In many small towns, people know a pot about you and you have plenty of nosy (for lack of a better term) neighbors. Arguably, they make for better watchers.
I would be interested to learn more about this. I have also live in multiple states and this doesn't sound like any of them. Municipalities always have some form of one of the following: mayors, councils, school boards, constables/police, magistrates, etc.
"Is there a reason to view things differently?"
Yeah. I see way more corruption at the county level than the local level. Most of the circumstances and scenarios I laid out in previous comments would not apply to county level officials, nor even to large municipalities. I was strictly speaking about small towns. The most important part is how information is gathered and spread. Small towns are notorious for information being found out and spreading rapidly. That oversight would not be the same in other settings. These mechanisms don't exist at the county level. They are far enough removed from their constituents that they can operate without the same watchful eyes.
Everyone from a small town has a tale of “that family of thieves” who you know to watch when they come in your store. Sometimes they are legit thieves, sometimes it’s just bias.
https://www.pewresearch.org/politics/2020/09/14/americans-vi...
The first thing this Celerbrite dudes need to do is to guarantee that the device gets a full reset before each use.
We as society we need to force our police and government to use only open source software, otherwise we don't know what backdoors or shit this guys put in, we could evaluate the code and see if we are wrongfully convicted by a shitty algorithm and transparency would also prevent (hopefully) people selling some open source software with a logo and a python script for milions.
I think it was more insidious. Police scans phone A and stores a log. Police scan phone B with said code on it, which infects the scanner. This code not only tampers with the logs for phone B, but goes back and tampers with the logs for phone A. There is thus no log that one can definitively say represents the true state of any scanned phone at the time it was scanned.
And the evidence logs are written in pencil
I wish we would stop trying to come up with analogies to computing concepts.
But since you insist: this is like the file folder came from Harry Potter and could be possessed by an evil spirit that could change the contents without your knowledge.
Analogies help those people are not familiar with the jargon or the field of study. You may be an expert in the computing concept, but the rest of us are not an expert in that field. Analogies is where it helps to understand it better.
So the answer is no, we can't stop using analogies.
Because that's what this does, it lets the data on a suspect's device potentially cause the software to run arbitrary code with elevated permissions, practically, you could use this to craft a packet of data that, when read by Cellebrite's software, simply shuts off the machine, or kills the Celebrite software, or, worse, connects to the internet and downloads some other payload to do something else. Cause there's no way these machines aren't connected to the internet at some point since the software validates its license that way.
At that point, you cannot trust any of the files in the building.
It's not a matter of operator error. This exploit works during normal operation of the software in question, it depends on the software being operated in a typical fashion.
It's not a choice of the person running the software. The only choice is to stop running the software.
It also calls into question all evidence ever collected by this program because we can't know if some other company already figured this out or not.
The crazy thing about this attack, is the person making the copy may never know until its presented in court and challenged. Then everything from the folder has to be thrown out.
Turns out that's actually a real thing...
https://www.dkriesel.com/en/blog/2013/0802_xerox-workcentres...
The standard is not as high as most technically-minded people think. Juries can convict defendants on the uncorroborated testimony of a single witness: https://newrepublic.com/article/152305/who-to-believe-sexual...
Infamous cases were difficult in the age of newspapers when they got hold of a story, but now everyone can begin their own agendum.
The game takes place in a slightly fictionalized version of Japan and is made by a Japanese game developer noted for making games steeped in contemporary Japanese culture. I guess that's important to note.
If you jokingly imply that jury duty is for suckers, you’re undercutting the system and supporting bad outcomes. For example, one of the few checks on the drug war or bad policing has been juries refusing to accept bad police work.
I didn't mean to be glib, but it got me dismissed immediately. It seems to me that any knowledge of law or procedure will get you dismissed.
point is, if you want to be on a jury, work hard NOT to give away any knowledge of the legal system.
I was asked about possible conflicts of interest and indicated that my father is an attorney who practiced in the same state. Asked for my profession, I replied that I am a bioinformaticist and was asked to explain the term. I said "I write computer code to help biologists analyze and use their data." This was in a university town. The prosecutor opined that I must be "pretty smart" and that she expected I came with an understanding of biology and biotechnology, all of which I affirmed. She asked if I would use that knowledge to assess DNA evidence that could be presented during the trial. I responded "No, I would limit my interpretation to only what was provided by testimony or otherwise affirmed during the trial." The prosecutor looked momentarily surprised at the precision with which my answer addressed the legal burdens required of a finder of fact, and then simply replied, "Ok, thank you." I was then immediately named to the jury.
Perhaps your attitude or delivery got you dismissed, or perhaps your choice of words suggested the opposite of what you imply here - a fundamentally flawed perception of the role of the prosecution? It's certainly technically correct that the prosecutor represents the state, not the victim, and that victim representation is its own ball of wax. Your reasoning, however, seems suspect. Paraphrasing: "Because the victim is not represented by the prosecutor, I have no problem with his not testifying." That's a non sequitur; the antecedent in no way implies the consequent. I could see the prosecutor rejecting you for appearing to be trying to impress (and failing) with your grasp of legal reasoning, fearing that you might not faithfully execute the court's instructions.
Then again, there are probably plenty of attorneys that just don't trust smart people.
And while that's likely a game you win, I also wear my seatbelt despite not betting on crashing my car.
I think most people know this and figure they’re just going to have to waste a few hours only to be sent home (or worse, get selected and then sent home after settlement).
> “Those who say there’s no corroborating evidence are thinking very narrowly,” Victor Vieth, the founder of the Gundersen center, told me. “They’re thinking of hair, DNA, the things you see on television dramas. I’ve never worked on a case of child abuse where, if you look hard enough, you won’t find corroborating evidence.” Vieth invited me to imagine a child who describes that his or her assault occurred in a room painted blue. Police should obtain a warrant and visit the room. Were its walls blue? If so, that was corroborating evidence.
This is of course not corroborating evidence that a sexual assault was committed. But sure, it corroborates that the room exists, and why would a child know what color the walls inside a room were unless they had been the victim of a sexual assault there?
This type of logic has been used plenty in court, it being in your possession, digital or not, is sufficient.
The claim here is that due to the vulnerabilities Cellebrite has, the offending item may never have been on your device. This is more similar to saying that the images the police took in your house of drugs were kept on an unsecured server, there are recorded vulnerabilities for it, and therefore the images could have been digitally edited to show drugs where none were present.
The problem is that a report about a phone scanned on 2020-02-01 can be altered by a phone scanned on 2020-05-01 to say that there was porn when there wasn't. Oh, and that scan left a running program which will cause 5% of the phones scanned after that to randomly also claim porn that is not on the device.
Therefore if a single phone with Signal was scanned at the kiosk, NOTHING from that kiosk can be trusted.
If the USER could select the action, for research purposes, that might a different story.
If he winds up in court, I'd love it if he sticks to his, "the files are there for artistic effect".
Saying those decorative files tampered with evidence is equivalent to admitting that everything the Cellebrite claims to do, it doesn't do and never has done.
In absence of write-once media, they are betting that the hashes they capture will be the same every time they image the device because they never modify the device.
On top of that, another way around this is under the confrontation clause. The accused has the right to question any witnesses against them. So I’d demand to cross examine the “tech” that ran the scan and make it apparent that no one knows how the box works (that’s the whole point; it’s proprietary). And then ask them simple questions like “cookies images have been placed on my clients device if no one knows how the box works?”
The real advantage of these celebrite boxes, for law enforcement, that they give them leads to otherwise admissible evidence. So that’s why I’m shocked to hear that they actually tried to use information from the phone.
Seriously, these things just use the built-in device backup and analyze it, you can even do it yourself for free using Autopsy which is a GUI for TSK.
I'm sure the answer to that would be delicious. ;)
Auto-correct was a mistake. Either that or a malicious undertaking cleverly disguised in the cloak of legitimate best intentions.
Could images have.
Unfortunately, I don't have faith in all defence lawyers to do this kind of thing - some "free because you're poor" lawyers might spend only 20 minutes per case...
Another possibility is that the investigators fail to share evidence as required.
Imagine a murder case where the accused claims he was at the cinema at the time. Often the police won't go to the cinema and get CCTV tapes to back up the claim - they'll just use blurry footage from the murder scene and claim "looks kinda like the same guy ish".
I suspect there are a lot of cases of innocent people in prison simply because evidence of them being innocent was deliberately overlooked or not collected.
A woman was found murdered in a cemetery. She was in town for a university-related festival/party, and was staying temporarily with some other students.
The police suspected the other students first, and went to their house, and found out:
1. One was an RPG player, had RPG books.
2. The other was a heavy metal fan and had heavy metal-related posters.
3. The other guy was into literature and had some 'dark' literature.
So conclusion of the officers: it was a satanic cult, and the woman was killed in a "RPG Satanic Ritual"
The prosecutor's office at first went with it too.
Later, already mid-trial, the prosecutor changed, the new prosecutor found a lot more formerly-useful now useless evidence that the police seemly deliberately ignored:
1. The police had in evidence storage some bloodied clothes that they never ran DNA tests on, the DNA was now useless (it has been years since the actual murder). Also the evidence was probably contaminated, the storage consisted of stuffing all the evidence in trash bags and leaving them in a random room in the police station.
2. People told the police multiple times, that the woman had drug debts, but they were ignored.
3. A known drug dealer was seen on the day past the murder, riding a bike around town, with his t-shirt having red stains on it, police even seen the guy themselves, and didn't bother stopping him and checking his t-shirt.
The new prosecutor despite seeing all this, had hands tied and just went along with what the police wanted, and tried to prove in court that they were "satanists".
The ruling was this (the judge was quite upset at it too):
1. The prosecution failed to prove they were satanists, evidence pointed out to the accused living there by coincidence, and their hobbies being "dark" or "fantasy" were coincidence too, only one of them was an RPG player, only one of them was a heavy metal fan, and so on, they didn't shared their hobbies with each other.
2. And even if they WERE satanists (they weren't), in Brazil being a satanist is not a crime.
3. For some reason the prosecution provided zero evidence that was actually related to the murder, they only tried to prove the accused were satanists and presumed this would be enough to know they were the murderers, but they never tried to link the accused with the crime scene, didn't even tried to explain when they would been at the cemetery.
I recently witnessed a case where a trooper charged the wrong statute. How can you make a thorough investigation if you don't even know the elements of the offense because you are looking at the wrong statute?
He made about 5 other mistakes too, even lying to the judge. The system doesn't care. The investigation into the lie was found to be a "just a misunderstanding" eventhough that same report also notes that the statement was false and that he made the correct version of that statement 10 minutes prior to that.
In my old agency, we were required to do that type of thing. For example, we had a rape case where the rape occurred in a short-stay house (kind of like a hotel, but for families that require room for multiple kids/pets, etc). The subject only rented the house for one night, and the rape occurred in one of the bedrooms. By the time we got to the house, there had already been another guest for the night between him checking out and us arriving. We went to housekeeping and interviewed the staff who cleaned the room, we dug through the trash to verify the drinks the victim claimed to have drank, we got camera footage from the gas station where he bought alcohol (she was also underage). There's a ton more that was done to verify key facts, most of which were essentially meaningless, but we did them because we are required to.
Now, imagine if a victim tells you a story that includes 10 things that could be independently verified (through searching a location for CCTV, pulling receipts, whatever) and you only look for 7 of those things. This opens up the defense to make an argument that you intentionally skipped looking for those other 3 things because they were exculpatory. It's impossible to think through all the different details that could be verified, along with their probative value to a case, and organizing them by how long you have until the evidence is no longer available (there's no standard timeframe for how long before a given store's CCTV recycles).
I'm not saying investigators shouldn't do this ground work, but I am saying that it's a shitload to ask of them and potentially opens up the prosecution to a very bad-faith defensive argument that certain seemingly-obvious factors weren't considered during evidence collection.
In your murder example, sure, they could say "looks kinda like the same guy ish" and hope that's good enough for a jury, but the defense can (and should) tear that to shreds. If a subject told us they were at the cinema at the time of a murder, my first thought would be to ask them to provide any evidence they themselves have (social media check-in, location data from their phone, receipts/credit card statement, etc), but I would also absolutely be checking the cinema for video evidence. If I can prove he lied, that's a huge win for the prosecution. Alternatively if he's telling the truth that he has a verifiable alibi, then the real killer is stacking up time while evidence entropies.
The reality is that cops are burdened enough that the only evidence that's persistently worth verifying are usually statements made by subjects. This is where case where it's worthwhile to talk to cops: if there is potentially verifiable evidence of innocence that stands a good chance of diminishing as time goes by. Giving specific details like the place and time that you saw a movie at a theater along with any receipts or ticket stubs, would be a huge factor in preventing future law enforcement / prosecutor interactions.
Might want to think twice about that, you might be replacing one allegedly innocent suspect with a suspect you know for a fact is innocent, yourself.
This is only true if the cops are actually looking for the Truth, not just a way to close the case as fast as possible.
You seem to have faith that the cops / prosecutors are attempting to find the truth, unfortunately I do not share your faith in the system. So the better plan, for your own personal safety, is to NEVER TALK TO THE POLICE [1]
They also don't maintain good Gugilo records. You can request that information, but they won't give it to you because they don't keep good records of the past issues, on purpose. I had a trooper contradict himself in court and official reports 3 or 4 times. The prosecution still found him to be a reliable witness. Anyone else would have their testimony thrown out.
Because they don't keep good records of these contradictions, I guarantee future cases requesting this information will not get it.
It's not like the default Android SMS app indicates that messages have been deleted. And there was no provenance information provided as to where or when they were collected.
I hate this, because screenshots come out looking like trash and it's very difficult with most messaging apps to show the timestamps for all messages. Eventually, this pendulum is going to swing (when cases start getting thrown out for this lack of timestamps/evidence of deleted messages, etc) and law enforcement (at least in the military environment) will have a bit more support in pulling relevant (and only relevant) data from victim devices for the purpose of evidence collection.
One additional thing about screenshots: They can be totally faked, and the "contact" can't be validated from conversation screenshots. For example, if you buy a burner phone, you can create a whole conversation as though the burner phone is the assailant, then change the contact's number to the real assailant. Some chat apps keep the whole conversation, despite the number change, in the same chat and make it impossible to tell which number sent the messages. Cellebrite indicates the number (assuming we're talking about SMS here) where the message came from, even if the contact changes.
My preference would be a process whereby cops run the Cellebrite extraction, then produce a report that's limited to the content the victim and her counsel agree to, like conversations between her and Bob, and conversations between her and Sally, but nothing more. This way, at least we have some data that is verifiable and detailed (would show the to/from numbers, contact info, times, etc).
These are consent-based searches, not warrantless.
The 3 points to Miranda rights are cops, custody, and questioning(provided the questions would reasonably illicit a criminal response).
For example, if I am a cop and I walk up to you on the street and ask you questions, your 5th amendment only applies if I'm not letting you go (custody). There's some ambiguity on the custody part, but it's usually revolving around the idea that you're under arrest. For the military, since you're always "Subject to the code(UCMJ)", the custody part of Miranda means that the only factors that matter for cops (and this is more broadly inclusive of authority figures or anyone who is a "mandatory reporter", meaning someone who must report criminal activity/statements to military law enforcement) and questioning (so, is the subject being asked questions that would elicit a criminal response). If I (a cop, commander, supervisor, whatever) I a subordinate a question that I know is likely to elicit a criminal response, that response (and the fruits of it) are inadmissible in court and cannot be used to further a criminal investigation. So, I can ask Private Dump "Hey Dump, what did you do this weekend?", and be fine, but if I ask "Hey Dump, how much Cocaine did you snort off that stripper's chest Saturday?", I would be eliciting a criminal response (assuming that I have reason to believe he was engaged in criminal drug activity on Saturday).
This tends to work in favor of the subject of an investigation, though, because they a) can't incriminate themselves without a rights advisement unless they willingly volunteer incriminating information in response to a question that wasn't likely/designed to elicit it and b) they have to waive their rights before asking these kinds of questions, so they know they are being investigated (and what for, since Article 32 advisements are WAY more thorough than Miranda).
As for your point about this and other amendments being mute for military, there are a couple ways to think about it. If a military superior or law enforcement conducts a search without search authorization or consent, the results cannot be used against you criminally, on administratively. Effectively, they could kick you out (but not with any of the negative flags, like a dishonorable), but they can't prosecute you. This applies to searches, asking questions without Art 32 advisements, etc. Effectively, your rights are still being respected and they're interacting with you like an employer, just with a bit more authority.