Moxie Marlinspike hacks the hackers (Cellebrite)

  • Be sure to checkout “Tips & Tricks”
    Dear Guest Visitor → Once you register and log-in:

    This forum does not automatically send notices of new content. So if, for example, you would like to be notified by mail when Steve posts an update to his blog (or of any other specific activity anywhere else), you need to tell the system what to “Watch” for you. Please checkout the “Tips & Tricks” page for details about that... and other tips!

    /Steve.
  • Larger Font Styles
    Guest:

    Just a quick heads-up that I've implemented larger font variants of our forum's light and dark page styles. You can select the style of your choice by scrolling to the footer of any page here. This might be more comfortable (it is for me) for those with high-resolution displays where the standard fonts, while permitting a lot of text to fit on the screen, might be uncomfortably small.

    (You can permanently dismiss this notification with the “X” at the upper right.)

    /Steve.

This is a very good story for security:


Basically, Moxie went out for a walk one day, saw a package fell off the back of a truck. That package was clearly marked Cellebrite and contained the latest software/physical hacking tools of Cellebrite.

Moxie then reverse-engineered Cellebrite’s hacking software and found their software riddled with LOTS of security holes. Basically, if Cellebrite’s software is used to try to hack a bobby-trapped device, the Cellebirite software itself will get counter-hacked. Moxie released a proof-of-concept code to do that!

If the Cellebrite software itself is counter-hacked, then all the forensic evidence it collected (both previously and presently) can be altered by the counter-malware. That means that in the context of law-enforcement, the collected ‘evidences’ produced by Cellebrite can be unreliable and thus, ought to be inadmissible in court.

And there’s a kicker. Moxie found that Cellebrite‘s software included copyrighted code from Apple. Given that Apple is so zealous about their intellectual property, and they have an interest in disrupting Cellebrite’s business model, we can easily foresee that Apple’s lawyers will soon go after Cellebrite like sharks going after blood.

Time for 🍿!
 

Barry Wallis

Magician in Training
Where I come from "fall off a truck" is a euphemism for helping oneself to something they're not otherwise entitled to.
True, but in this case its not a euphemism, he says he literally saw it fall off the truck and he doesn't say he made any effort to contact the owner.

My apologies in advance, I am an inveterate pedant.
 

miquelfire

I like red!
Sep 26, 2020
42
4
www.miquelfire.red
There's a chance he made up the fall of a truck story and went far enough to show it on the ground to make that story believable. Like he bought it via a way he doesn't want to be closed off from being able to buy it again.
 

Barry Wallis

Magician in Training
There's a chance he made up the fall of a truck story and went far enough to show it on the ground to make that story believable. Like he bought it via a way he doesn't want to be closed off from being able to buy it again.
I don't see why he would. It increases his chances of getting arrested or sued or both. All he needed to do was not say anything about how he got it.
 

miquelfire

I like red!
Sep 26, 2020
42
4
www.miquelfire.red
If the reason the way he got it was staged, it might be to protect the actual buyer. Cellebrite might not allow some random person to buy their products so Moxie can't really buy it directly from them as a result, but he knows someone who can.
 

danlock

Well-known member
Sep 30, 2020
133
45
Should we focus on how he got it or on what he did with it? It seems like we've focused on the former to some extent which might be nearly enough; barring any new information of significance pertaining to the former, perhaps we should start shifting toward discussion of the latter.

:)
 
  • Like
Reactions: DiskTuna