Cellebrite asks cops to keep its technology secret
techcrunch.com
techcrunch.com
Were I such an attorney, I’d campaign to taint the reputation of Cellebrite and make the evidence it generates completely untrustworthy.
You'd be surprised. The courts are not scientific debate arenas. Burn forensics? Pseudoscience. Bite mark forensics? Pseudoscience. Lots of DNA-based forensics? Totally unreliable. Firearms ballistics forensics? Laughable pseudoscience. Polygraph tests? Laughable pseudoscience. Field sobriety tests / "drug recognition expert" certifications? Lol, lmao even.
All of this nonsense has been successfully used to convict people in court. Turns out, putting someone with PhD after their name or a white lab coat or a phony certification on the stand tends to work for prosecutors.
New York's main crime lab completely blew DNA testing, and thus rendered all of their results worthless. This went on for many years. Instead of rectifying their mistakes, they swept it under the rug and forgot about it. To this day, thousands of people are in jail based upon wildly incorrect "science".
It is rather unsettling to know that nearly everything the criminal justice system uses is no better than voodoo, and you are not far away from getting thrown behind bars for little more than the whimsy of people who are empowered to do so.
But Cellebrite is unambiguously a private, for profit enterprise. They haven't established themselves as a "science" like authority in the average person's eyes, they actively avoid explaining the processes. They're just a company paid by a customer to deliver what the customer wants. So in the average person's eyes the difference should be obvious: this isn't science, it's not for everyone (just for the Police), and the people are not allowed to peer behind the curtain. And like authorities like to say "honest people don't need to hide things".
So as far as jury trials go there may still be a fighting chance.
I suspect that the real issue is the lack of incentive; it doesn't matter whether they know (or are capable of figuring out) that their science is bunk if there's no consequences for the status quo to continue.
Yeah, that should be a crime. Their fraud led to false imprisonment
There's really no incentive for forensic science to be a science at all, at the end of the day. You're either working for cops, and paid for evidence to convict their suspect, or working for the defense, and paid to convince us the cops are wrong. There's no one paid to tell us what reality we're in.
Even today, Large scale experimental science seldom get review from outside their lab. (Because the lab literally hire every expert in that sub-field)
Calling something "not science" because it is not peer reviewed is just ignorant
https://www.justice.gov/opa/pr/owner-polygraph-indicted-alle...
Clearly our government and legal system think highly enough of the technique to include it in interview processes. The NSA even has an entire production video rebuking the criticisms of polygraph. It’s not just a tool (in the eyes of the government) used to trick dumb criminals into spilling the beans.
Perhaps its being used as a tool to evaluate a person in other ways. For example, you're generally not arrested for admitting to crimes like smoking weed or stealing candy bars from a gas station. But admitting to crimes, or morality divergence (such as adultery), can mean with enough effort a smart intelligence organization could manipulate you.
It has nothing to do with "maintaining the shroud of 'this works'" because it does work for the purpose they have. It doesn't need to be 100% accurate or admissible in court.
Au contraire
Did that case against polygraph.com ever go to trial? Sounds like a slam-dunk free speech case, but I imagine the DOJ was willing to settle for anything to avoid that being fought in open court.
They know it's just part of the system, and the routine.
These folks have a slightly different mindset, and, I think, view procedures as important to weed out people who might cut corners, lean into their ego (how dare they make ME take a polygraph), or be careless with information. A nice side effect of this process is it selects for humility, openness, and conscientiousness.
And they view the work they do as hugely important for the security of their nation. Including those who laugh at them for their chosen profession.
They were some of the most professional, conscientious, diligent, and excellent technologists I've ever worked with. Definitely on par with anyone at FAANGs or startups that I've work in.
Or perhaps it selects for submissive, controllable automata that will go along with anything, with no limit on absurdity. Your rationalization of this stupidity is embarrassing.
But I do want to dispell the idea that people are less intelligent, less capable, or somehow mindless just because they disagree with you about this (Or OP), and choose to be part of it.
> They were some of the most professional, conscientious, diligent, and excellent technologists I've ever worked with. Definitely on par with anyone at FAANGs or startups that I've work in.
such a shame they choose the most absolute evil actor to use those qualities for. which brings me to
> conscientious
yeah.... I think its pretty much impossible not to know what evil lives openly in those places
You can get false confessions on a polygraph interview but you can also get them in a normal police interview eg with the Reid Technique.
Thousands of people are in prison right now over failed polygraphs.
In places with strong courts that won't put up with this, probation officers simply tell the therapist to write up the probationer for some other, vague non-compliance issue should they fail enough polygraphs
What kind of justice system do we have where whether or not people have had lunch is the biggest factor in outcomes?
2. Whether or not people have had lunch is not the biggest factor in outcomes. The most important thing you can read about this study is Daniel Lakens' commentary:
> I appreciate that people have tried to think about which mechanism could cause this effect, and if you are interested, highly recommend reading the commentaries (and perhaps even the response by the authors).
> But I want to take a different approach in this blog. I think we should dismiss this finding, simply because it is impossible. When we interpret how impossibly large the effect size is, anyone with even a modest understanding of psychology should be able to conclude that it is impossible that this data pattern is caused by a psychological mechanism. As psychologists, we shouldn’t teach or cite this finding, nor use it in policy decisions as an example of psychological bias in decision making.
> If hunger had an effect on our mental resources of this magnitude, our society would fall into minor chaos every day at 11:45. Or at the very least, our society would have organized itself around this incredibly strong effect of mental depletion. Just like manufacturers take size differences between men and women into account when producing items such as golf clubs or watches, we would stop teaching in the time before lunch, doctors would not schedule surgery, and driving before lunch would be illegal. If a psychological effect is this big, we don’t need to discover it and publish it in a scientific journal - you would already know it exists.
> I think it is telling that most psychologists don’t seem to be able to recognize data patterns that are too large to be caused by psychological mechanisms. There are simply no plausible psychological effects that are strong enough to cause the data pattern in the hungry judges study. Implausibility is not a reason to completely dismiss empirical findings, but impossibility is.
( https://daniellakens.blogspot.com/2017/07/impossibly-hungry-... )
If you do read the other commentary, it is clear that the reason the rate drops to zero before breaks is that cases are scheduled with an eye toward not running into the break. The 0% grant rate causes the just-before-the-break timing, not the other way around.
The only legitimate analysis they’re doing is ammo brand matching. “Hey, there was a Sellier & Bellot 380 Auto casing at the murder scene. The suspect had S&B 380 in his gun safe. We got him.”
Find some 1 in 1000 match. Find another 1 in 1000 match. Claim they're independent, so the chances of both of these are 1 in a million.
What they don't say is that there are 5000 things you can test that each have a 1 in 1000 chance, so you should expect to find ~5 at random if you test them all. The 1 in a million chance is if you choose 2 of the 5000 at random, test only those and they both match; not if you systematically run tests that only notify you when they find one of the matches.
Most criminals subject to this are probably caught because they loaded the magazine without gloves and left a fingerprint on the casing that gets completely etched into it on firing. Or, you know, police do actual police work and pressure the right people into narc'ing on the suspect.
[1]: https://radleybalko.substack.com/p/devil-in-the-grooves-the-...
Seems like markings can be exculpatory at best, for instance that casings or bullets clearly don’t match, but that the “unique markings” of an individual barrel is complete BS, especially with precision mass production of modern firearms. But in practice, it seems to rarely exonerate suspects, even if the evidence exists.
Still there is certainly problems relating to the fact that people without money cannot easily produce counterargument and let "real" scientists present counterhypotheses. Further there are incentives to sell products to law enforcement that produce simple truth (I would by a product from a critical scientist). Also I think it is human rights problem, if states do not have to fully compensate the damages produced by applying known faulty technology as many other actors would have to.
Once again, I’m skeptical of many supposed sciences as well, but I’m just as skeptical of internet commenters that claim entire fields of expertise and science are all pseudoscience and made up.
For all the other claims (e.g. polygraph), you can easily search for more information online.
The point is that authority or lack there of should not be a part of your evaluation of the claims, on either side.
The point I’m making is I’m definitely not qualified to analyze all these claims that you’re making in support of these being pseudoscience. Sure your claims sound reasonable, but people also thought the earth being the center of the universe sounded reasonable. The thing I like about hacker news is people usually don’t just make unsubstantiated claims, and when they do they usually get gut checked by opposing views, which is a good thing.
And OP didn’t really make any claims, they just listed a bunch of fields and said they were all pseudoscience. I appreciate the fact that you’re at least giving an explanation as to why it’s not considered science.
Why put the onus of the work to quote a bunch of articles on the OP when these are all very easily verifiable with a tiny bit of effort
Drug metabolites are measured repeatedly and precisely, assuming no one mislabeled anything and the machine is well-calibrated and the technicians are honest even though they know who chooses which lab to use and the sample was collected fastidiously and not contaminated with anything.
But drug metabolites aren't drugs. Eat a bagel with poppy seeds and you can test positive for opioids. Take certain decongestants and you can test positive for meth.
Law enforcement does all sorts of sketchy things in order to get a conviction. Why is it a surprise that they use pseudoscience that juries eat up because they've seen it used in their favorite police procedural TV show hundreds of times?
https://www.iflscience.com/lsd-dna-pcr-the-strange-origins-o...
yes that was a very colorful person.
Plenty of Signal users live in totalitarian dictatorships, where the law doesn't care if you're actually guilty. Even in democracies you can't always rely on the courts. "We're planting incriminating evidence on your phone" should lead to mass uninstall of Signal.
Except nobody really believes they did that. Signal would be banned from all App Stores, and moxie would go to jail on so many charges. It's one of those nerd law ideas where 'you can't 100% prove it' is the golden defence except it isn't really - the law can call a bluff, especially when millions of users and multiple app stores already did. It says reasonable doubt, not any doubt.
I was on a jury where the defense counsel eviscerated an expert witness from a red light camera company. The police used the cellular/gps time on the camera to splice together 10-12 videos from various camera whose times weren’t in sync.
Having impeached the time; the whole case fell apart and her client’s manslaughter charge was dismissed.
In fairness, the guy was there to talk about a camera, not to describe how NTP on the cellular network works. The defense had the judge questioning the nature of time and space!
1. most cases are about sms text contents and timestamps. these can be externally validated from the phones themselves, other software, or from having both sides of the conversation
2. other data, like location, is less certain, needs to be validated, and there are debates about what the evidence means,
3. Cellebrite software is available to people who pay for it on both sides and their training videos encourage LEO to actually go out and validate the results they see. the constantly changing cat and mouse nature of cellphone extraction and parsing requires double checking and validation. this is the big issue. LEO generally have no tech skills and are just armchair phone extractors. they do not validate the data. that is a problem, but not the tool itself.
The prosecution would present the Cellebrite 'evidence' to the judge and (in our scenario) it would move the needle towards the prosecution. Then the defence will (always) try to doubt the evidence and move the needle back, but it would take a lot more than 'something might have happened, dunno how' to do that fully. When the needle is tilted enough, the prosecution has their conviction. Note that in our reality, judges have a lot of trust in prosecutors, and the needle always starts tilted...
* Such a conspiracy would have to include Cellebrite, the police and Apple/Google. After all, hacking the phone likely means you have the iCloud keys and can download the backups to verify. Furthermore, the conspiracy would always be at risk from the accused choosing to restore the backups to show some evidence wasn't there. So someone at Apple/Google would have to be complicit as well to modify the backups.
Science also works probabilistically, like most of it, but the law works "probabilistically", as in eyeballing a rough estimate using folk theories kind of probability.
They seize your phone and pull photographs, text messages, messenger logs, maps data, etc. The messages are inculpatory.
What do you want to say? That the extraction method is unreliable, that the Police have incorrect logs? Imply that the text messages have been extracted with errors, somehow?
That simply isn't the case. The data extracted is both reliable and probative. This is a copy and paste.
Debatable.
Also, I couldn't help but be amused by cheekiness:
"By a truly unbelievable coincidence, I was recently out for a walk when I saw a small package fall off a truck ahead of me. As I got closer, the dull enterprise typeface slowly came into focus: Cellebrite. Inside, we found the latest versions of the Cellebrite software, a hardware dongle designed to prevent piracy (tells you something about their customers I guess!), and a bizarrely large number of cable adapters."
But normally people just look at the reality and go "oh yes, this tool extracts the stuff on a phone and turns it into a pdf/html, how convenient". 99.99% of the time, the time a drug dealer alleging he has no knowledge of the 100's of deals on his phone is about as realistic as your 5 year old nephew with cake smeared on his face denying he ate the last bit of cake... and is treated as such. Should the act of selling drugs be a crime?- completely different topic.
You cannot assume a random company's tech works reliably without any proof, if someone's life is at stake. If yhry have cloud upload shenanighans they could be mixing up records of different people.
Evidence from a network probider is a completely different matter, but if SMS records are enough you would not need this crap.
And I believe that's what the argument against secrecy with these systems is. How can you know whether legal lines have been crossed if the system is shrouded in secrecy?
In theory, a CP felon would have reason to generically hack some another computer (since CSAM storage itself is illegal), and desktop OSs are less secure. In the phone case, you likely need to assume a specific criminal conspiracy entirely meant to convict the defendant, one that must involve the police*, and that's an extremely high bar to meet.
* The police are the ones using the tool; the only way to effectively plant non-generic evidence is to have the corroborating data first and that requires police assistance.
Please share what you know, because that'd be huge news. The last info we had is that even the FBI had trouble getting into a locked 4S and the protection has improved significantly.
After that the info was that Graykey(?) could bypass the attempt limit on passcodes, but by having an alphanumeric code you could make brute forcing take longer than our Sun has life left in it.
In many cases this is not what happens. An average iPhone doesn't run the very latest iOS, the model might be old as well, and pass code may be super primitive.
Snowden has revealed they are more than happy to let agencies into their supply chain.
No, we know that from the words of independent security experts.
Knowing this allows users to improve their protection and privacy at the cost of convenience. For instance, one can avoid using iCloud altogether, or choose to encrypt iCloud backups.
[1]: https://arstechnica.com/tech-policy/2014/05/photos-of-an-nsa...
Apple devices get so much attention that the risk of tainting huge batches of devices at the supply chain level and having one of those end up in the hands of a security researcher is too big.
All of the security professionals I know use iPhones just because it's really fucking hard to get anything out of them without resorting to rubber-hose crypto, which is illegal in most of the world.
The last iOS zero-day was burned on no other than Jeff Bezos.
Joe Schmoe is perfectly safe, the local PD won't have access to tooling like that.
The amount of shills, purely positive news, accepting all their PR without questions, ignoring all that happened in the past... not all members, but some very highly voted opinions makes me think this place simply can't be objective on this topic.
Probably hundreds of Apple employees come here quietly and stay quiet on relevant topics, but folks either paid or simply fanatical about this specific brand make any serious discussion impossible.
I dont blame the company, its for profit mega corporation just like the rest doing same things as everybody else on the market (ie not paying taxes where it should to support local development, happy with chinese child labor in contractors etc), but some people refuse to see that. Its not unique to electronics, but one would expect a bit more rational and balanced discussion on them.
iirc the feds complained bc they wanted apple to give them access for free and not have to use/buy 3rd party tools
The Greykey device plugs into the phone, requires the phone to not have been powered off. The untrusted USB settings also help prevent it from working.
Also, iCloud backup and several other dangerous "features" like iMessage are enabled by default whenever you sign in to iCloud so there's a few backdoors already standard to anyone who uses iCloud. If you sign in in settings, it automatically signs/opts you into iCloud, even if you don't want it.
cloud backups are also very problematic because they contain a lot of sensitive information and are not safely encrypted.
> If you choose to enable Advanced Data Protection, the majority of your iCloud data — including iCloud Backup, Photos, Notes, and more — is protected using end-to-end encryption. No one else can access your end-to-end encrypted data, not even Apple, and this data remains secure even in the case of a data breach in the cloud.
Which requires you first setup 2fa, which itself requires 2 keys.
https://support.apple.com/en-us/HT212520
I’d be more worried about these ota security patches they can send out whenever and how easily it is to MITM that process and send down exploited security patches. I’m sure it’s already happening in the wild
Metadata means nothing.
I assume the advantage here is the Apple difficulty to access these devices?
Copyright and corporate secrets apparently trump personal privacy and secret keeping in our world.
Also, I couldn't help but be amused by cheekiness:
"By a truly unbelievable coincidence, I was recently out for a walk when I saw a small package fall off a truck ahead of me. As I got closer, the dull enterprise typeface slowly came into focus: Cellebrite. Inside, we found the latest versions of the Cellebrite software, a hardware dongle designed to prevent piracy (tells you something about their customers I guess!), and a bizarrely large number of cable adapters."
https://arkadiyt.com/2019/10/07/pair-locking-your-iphone-wit...
Not that any of this matters anyway. Cellebrite doesn't let you extract from modern phones anymore. You send it to a lab and get back an image you dump into physical analyzer. The actual exploitation of the phones is done by them so they don't have to worry about leaks.
That’s not correct. Check out parallel construction[0] to see the lengths cops will go to in order to make it look like they have a plausible process to have acquired evidence.
The defense can question or challenge the methods, but that is not a material part of the prosecutions case.
As for parallel construction, Herring v. US opened it up as a legitimate investigative process.
Secret / Magic / black box processes can’t generate admissible evidence in criminal proceedings in the US.
If you want to challenge the reliability or accuracy of the process you need to have some basis to show the judge there is a thread to pull on and it isn't just a fishing expedition.
For an idea of how courts handle this, look at breathalyzers. People occasionally get the bright idea to ask to inspect the source code of the machine, and it is routinely denied because it is not in the possession of the prosecution. https://digitalcommons.law.uw.edu/cgi/viewcontent.cgi?articl...
Isn't this a reasonable ask?
It is shocking and disgusting how ignorant the legal profession is about any real kind of science and engineering.
Speed cameras?
False, chain of custody is needed, or .. cough cough .. bad cops will set you up.
The article mentions a training video that demos the product, yet didn’t include it as far as I can tell. Why is that not being published? I don’t want a transcription of a company telling cops to protect their property, I want to see what this company is able to access when they illegally access my property.
Pretty sure if I access a computer system that I’m not authorized to, aka, hacking, I just committed a federal offense, yet a company is legally selling the ability to do that very thing, at scale, to law enforcement and telling them to keep it a secret. Last I checked, a law was a law, and it applied to everybody, not just us common folk.
Also, “certainly mention premium” is rich. So don’t disclose the illegal hacking internals, but do give a shout-out and free marketing for our premium product, so others in gov and law enforcement will see what you got from them and go signup. Shit, do they have a referral bonus to? Get on the stand and mention premium and the referral code WHOWATCHESTHEWATCHERS for 60% off your first month.
What the fuck? How are these companies allowed to do this? Oh right, because their customers are the ones who would normally be arresting them, so it’s fine to break the law.
https://www.reuters.com/article/us-apple-fbi-icloud-exclusiv...
Now Apple no doubt would love to do some RE on these devices to identify and patch any exploits they use, and many of the local PDs that can get Cellebrite to sell them these boxes probably will abide by these terms, having previously been convinced via Apple/FBI propaganda that Apple is opposed to cooperating with law enforcement.
It's a little bit funny, but I think Apple security will win out in the long run as it only takes one instance of a leak for Apple to patch a vulnerability, and they do have a lot of money (and the cooperation of the FBI/DHS et al). The text of the training quoted in the article makes it seem that Cellebrite knows they are fighting an ultimately losing battle there, as information never becomes more secret over time, only less so.
Apple was very open about the fact that law enforcement would have access to the iCloud backup, which is even mentioned in the article you provided. And there was no "backdoor explicitly preserved" for the FBI, the iCloud backup was just not e2ee. This was also (somewhat) common knowledge at the time and what was often suggested was to do backups through iTunes because there was still an option available to encrypt the backup.
https://www.teeltech.com/mobile-device-forensics-equipment/m...
https://tritechforensics.com/digital-forensics/df-faraday-pr...
https://arrowheadforensics.com/products/evidence-packaging/f...
Apple has whitepapers, but they're about as verifiable as LK-99 in-practice. Their security model entirely revolves around the Apple-issued root of trust, and if you can't trust them then you have to hit the bricks. If you don't own both ends, the end-to-end encryption shtick is a theatrical farce.
How would that backdoor even look like? A some sort of master key that can decrypt every Bitlocker encrypted drive? Imagine if something like THAT got leaked.
Who would have access to that key? Microsoft themselves? NSA? FBI? What about the UK, Australia or other US allies? Do their alphabet boys also get access to this?
Do small town cops also get access?
And I'm pretty sure lots of security researchers have tried to find vulnerabilities of Bitlocker. If there was something fishy going on - they would have noticed.
living in a world where you run everything yourself sounds good in practice but then you can’t communicate with anyone else.
i’d like for the firmware to be open source and for the cloud to be federated, but it’s a pipe dream and i’m busy so i just gotta trust apple in the end
Until it's on by default for new iCloud accounts and previous non-e2ee iCloud accounts get automatically upgraded to use it, the fact that it is offered is basically irrelevant.
Additionally if you are using it to protect your iMessages, it's ineffective, as your iMessages are stored on Apple servers twice: once for each end of the conversation. Unless both you and the other end of your conversation have both explicitly opted in to e2ee for iCloud, a single party enabling the setting does nothing for the security of iMessage, given that approximately nobody uses the feature today.
I also didn't live in Nazi Germany under the SS and Gestapo but I can still recognize and identify that police surveillance over the private communications of all (or even a significant fraction of all) members of society silently and discreetly creates a world which sucks for everyone in it, as things like new political parties or new labor unions (or any other threat to the status quo) will be detected and defeated before they ever gain popular attention or critical mass.
Did we already forget OWS and the tea party? How about MLK?
Please stop using defined psychological disease terms to describe people who seek basic human rights to privacy from corporations and the state. It's disrespectful to both people who suffer from paranoid delusions as well as sane people who desire human rights.
What? To exonerate means not to find someone a criminal. It specifically has the nuance of finding someone not guilty due to careful consideration of the facts of the case. Someone who gets off on some technicality has not been exonerated.
Throw that shit out the window.
https://web.archive.org/web/20230819193912/https://techcrunc...