Burma Times

Saturday, Feb 22, 2025

Signal founder: I hacked police phone-cracking tool Cellebrite

Signal founder: I hacked police phone-cracking tool Cellebrite

Moxie Marlinspike accuses surveillance firm of being ‘linked to persecution’ around the world

The CEO of the messaging app Signal claims to have hacked the phone-cracking tools used by police in Britain and around the world to extract information from seized devices.

In an online post, Moxie Marlinspike, the security researcher who founded Signal in 2013, detailed a series of vulnerabilities in the surveillance devices, made by the Israeli company Cellebrite.

Marlinspike says those weaknesses make it easy for anyone to plant code on a phone that would take over Cellebrite’s hardware if it was used to scan the device. It would not only be able to silently affect all future investigations, but also to rewrite the data the tools had saved from previous analyses.

Marlinspike has been an outspoken critic of Cellebrite since the company claimed to be able to “break Signal encryption”, a claim the hacker has dismissed. “Cellebrite makes software to automate physically extracting and indexing data from mobile devices,” he says. “Their customer list has included authoritarian regimes in Belarus, Russia, Venezuela and China; death squads in Bangladesh; military juntas in Myanmar; and those seeking to abuse and oppress in Turkey, UAE and elsewhere.

“Their products have often been linked to the persecution of imprisoned journalists and activists around the world, but less has been written about what their software actually does or how it works.”

Police forces around the world use Cellebrite’s technology to help in digital investigations, particularly when they have managed to get hold of a physical device owned by a suspect or person of interest. While Cellebrite has been linked with attempts to bypass encrypted devices, the majority of its tools are built to allow digital forensics teams to extract information from unlocked, powered-on devices, and automate the sort of searches they could theoretically do by hand on the phone itself.

But through reverse-engineering one Cellebrite device (Marlinspike claims he acquired the device “when I saw a small package fall off a truck ahead of me”), Signal’s founder says he found more than 100 security vulnerabilities, just one of which could modify “not just the Cellebrite report being created in that scan, but also all previous and future generated Cellebrite reports from all previously scanned devices and all future scanned devices.”

“Any app could contain such a file, and until Cellebrite is able to accurately repair all vulnerabilities in its software with extremely high confidence, the only remedy a Cellebrite user has is to not scan devices,” Marlinspike says. In a winking suggestion that his company has placed such a booby-trap inside its own app, Marlinspike adds that “in completely unrelated news, upcoming versions of Signal will be periodically fetching files to place in app storage. These files are never used for anything inside Signal and never interact with Signal software or data, but they look nice, and aesthetics are important in software.”

In a statement, Cellebrite said: “Cellebrite enables customers to protect and save lives, accelerate justice and preserve privacy in legally sanctioned investigations. We have strict licensing policies that govern how customers are permitted to use our technology and do not sell to countries under sanction by the US, Israel or the broader international community. Cellebrite is committed to protecting the integrity of our customers’ data, and we continually audit and update our software in order to equip our customers with the best digital intelligence solutions available.”

Newsletter

Related Articles

Burma Times
0:00
0:00
Close
Reddit Blackout: Thousands of Communities Protest "Ludicrous" Pricing Changes
US and European Intelligence Agencies Uncover Evidence of Ukrainian Role in Terror Attack on Nord Stream Pipeline
A provocative study suggests: Left-Wing Extremism and its Unsettling Connection to Psychopathy and Narcissism
Neuralink Receives FDA Approval for First-in-Human Clinical Study
A Real woman
China and Brazil have signed a new deal that will allow them to trade in their own currencies, bypassing the US dollar as an intermediary
Brand new security footage has just been released to the public showing the Active shooter Audrey Elizabeth Hale drove to Covenant Church School in her Honda Fit this morning, parked, and shot her way into the building
Is Gold the Ultimate Safe Haven Asset in Times of Uncertainty?
Double standards: UK lawmakers attack EU chief over Ireland claims
A woman's Abusive And Violent Meltdown On Flight, Arrested
King Charles of the UK has pulled out of the cop 27 conference on climate change
Pfizer CEO Albert Bourla got COVID again
UK urged to brace for economic storm
Women's own body dissatisfaction appears to influence their judgment of other women's body sizes
NATO launches biggest military buildup since end of Cold War
Captured Britons sentenced to death in Ukraine
Facebook-owner Meta Platforms' Sheryl Sandberg to leave after 14 years
Comments on "Human Intelligence in a Digital Age" - A brilliant Speech by MI6 Chief Richard Moore, and the elephants neglected in the room
Bitcoin: BoE Deputy Gov wants to cancel democracy and protect the banks with regulations which infringe on people’s freedom, independence and benefits they get from their own money.
What are the Pandora Papers?
Taiwan-China relations at their 'worst in 40 years'
The attempt to hold Epik.com accountable for the content of its clients' websites is like blaming Gutenberg for the NYT's fake news that dragged the US into the pointless war against the nuclear weapons Iraq never had
Myanmar Facing 'Alarming' Risk Of Escalating Civil War: UN Rights Chief
Thousands of civilians flee Myanmar town after military clash with rebels
Students see full-day classes amid walk-in jab expansion
×