MacMusic  |  PcMusic  |  440 Software  |  440 Forums  |  440TV  |  Zicos
cellebrite
Search

Signal CEO Hacks Cellebrite iPhone Hacking Device Used By Cops

Wednesday April 21, 2021. 09:21 PM , from Slashdot
FlatEric521 shares a report: Moxie Marlinspike, the founder of the popular encrypted chat app Signal claims to have hacked devices made by the infamous phone unlocking company Cellebrite, which has famously worked with cops to circumvent encryption such as Signal's. In a blog post Wednesday, Marlinspike not only published details about the new exploits for Cellebrite devices but seemed to suggest that Signal's code could be theoretically altered to hack Cellebrite devices en masse. 'We were surprised to find that very little care seems to have been given to Cellebrite's own software security. Industry-standard exploit mitigation defenses are missing, and many opportunities for exploitation are present,' Marlinspike wrote in the post. 'Any app could contain such a file, and until Cellebrite is able to accurately repair all vulnerabilities in its software with extremely high confidence, the only remedy a Cellebrite user has is to not scan devices.'

Marlinspike claims (whether you believe this portion of the post or not is up to you) that while he was on a walk he happened to find a Cellebrite phone unlocking device: 'By a truly unbelievable coincidence, I was recently out for a walk when I saw a small package fall off a truck ahead of me. As I got closer, the dull enterprise typeface slowly came into focus: Cellebrite. Inside, we found the latest versions of the Cellebrite software, a hardware dongle designed to prevent piracy (tells you something about their customers I guess!), and a bizarrely large number of cable adapters.' Along with his colleagues, Marlinspike analyzed the device and found that it included several vulnerabilities that could allow an attacker to include an 'otherwise innocuous file in an app' that when it gets scanned by a Cellebrite device exploits it and tampers with the device and the data it can access.

Read more of this story at Slashdot.
rss.slashdot.org/~r/Slashdot/slashdot/~3/V3HMgdc4yO0/signal-ceo-hacks-cellebrite-iphone-hacking-devi...
News copyright owned by their original publishers | Copyright © 2004 - 2024 Zicos / 440Network
Current Date
Apr, Tue 16 - 18:28 CEST