Cellebrite asks cops to keep its phone hacking tech ‘hush hush’ | TechCrunch::For years, cops and other government authorities all over the world have been using phone hacking technology provided by Cellebrite to unlock phones and In a leaked video, a Cellebrite employee urges law enforcement customers to keep their use of its phone hacking technology secret.
Anyone know what Cellebrite can hack these days? I thought many of the latest phones and software versions had closed their vulnerabilities. Does anyone have data on which phones and OS versions are still vulnerable?
I very briefly worked for one of their competitors a few years back. These devices are pretty much limited to whatever you can do with root on android or jailbreaking iOS. If a person has a modern phone and a good sense of op-sec, chances are they can’t get much. These things basically work by doing backups then analyzing those backups offline, searching in known locations for non-encrypted databases and images. On android they can also do things through adb, like automated screenshots.
If you hand the cops a powered off non-rooted,locked bootloader, non-jailbroken phone and use e.g. signal, there’s not much they’ll be able to see. Of course, there seem to be other firms that operate at a higher level, and have some encryption breaking capabilities, but that’s not going to be accessible to your average cop.
My wife works an cellebritete. Its a device you connect to any phone and it gets evidence police is looking for. It can scan ANYTHING on the phone in seconds. This includes messages in applications, phone calls, images, appilcation data. Anything.
The smart thing about this is (if used under legal hands under a non corrupt government/entity) is it can be set up to only spit out relevant evidence by some search predicate / criteria and nothing else incriminating.
So for example if someone is arrested for kidnaping and they want to know if the suspect is really a kidnapper and maybe where the victim is it can spit out anything related to the case in question but nothing else incriminating on unrelated stuff.
It does this in under a set of rules admissible in court. IE the evidence cannot be tampered with (even by police) , it assures that the evidence is actually from that specific phone and wasnt touched, changed, modified and norhing was added in and so on…
Yeah, but phones have encryption and security. In order to get access to the data on the phone, cellebrite is hacking the device to circumvent the security measures and break the encryption, which is illegal for any individual to do, and should also be illegal for a corporation to do (corporations are individuals, legally speaking).
Phone manufacturers do not want companies like cellebrite breaking into their devices because it can be used for nefarious purposes. If cellebrite can get in, any other hacker can get in. So, phone makers are always closing these security vulnerabilities where they can find them.
Cellebrite is (hopefully) used under the law. They either get warrant or use a perpetual warrant on urgent security stuff. At least in countries with proper laws and abiding police.
Hackers sure indeed can use the insecurities cellebrite is using. But cellebrite has massive amount of budget for finding insecurities which normal hackers / people lack.