28 March 2022

How Thieves Can Hack and Disable Your Home Alarm System

When it comes to the security of the Internet of Things, a lot of the attention has focused on the dangers of the connected toaster, fridge and thermostat. But a more insidious security threat lies with devices that aren’t even on the internet: wireless home alarms. Two researchers say that top-selling home alarm setups can […]



When it comes to the security of the Internet of Things, a lot of the attention has focused on the dangers of the connected toaster, fridge and thermostat. But a more insidious security threat lies with devices that aren't even on the internet: wireless home alarms.

Two researchers say that top-selling home alarm setups can be easily subverted to either suppress the alarms or create multiple false alarms that would render them unreliable. False alarms could be set off using a simple tool from up to 250 yards away, though disabling the alarm would require closer proximity of about 10 feet from the home.

"An attacker can walk up to a front door and suppress the alarm as they open the door, do whatever they want within the home and then exfiltrate, and it’s like they were never there," says Logan Lamb, a security researcher at the Oak Ridge National Lab, who conducted his work independent of the government.

Lamb looked at three top brands of home alarm systems made by ADT, Vivint and a third company that asked that their name not be identified. The Vivint system uses equipment manufactured by 2Gig, which supplies its equipment to more than 4,000 distributors.

Separately, Silvio Cesare, who works for Qualys, also looked, independent of his job, at more than half a dozen popular systems used in Australia, where he lives, including ones made by Swann, an Australian firm that also sells its systems in the U.S.


No matter what the brand or where they're sold, the two researchers found identical problems: All the wireless alarm systems they examined rely on radio frequency signals sent between door and window sensors to a control system that triggers an alarm when any of these entryways are breached. The signals deploy any time a tagged window or door is opened, whether or not the alarm is enabled. But when enabled, the system will trip the alarm and also send a silent alert to the monitoring company, which contacts the occupants and/or the police. But the researchers found that the systems fail to encrypt or authenticate the signals being sent from sensors to control panels, making it easy for someone to intercept the data, decipher the commands, and play them back to control panels at will.

"All of the systems use different hardware but they are effectively the same," Lamb says. "[They're] still using these wireless communications from the mid-90s for the actual security."

The signals can also be jammed to prevent them from tipping an alarm by sending radio noise to prevent the signal from getting through from sensors to the control panel.

"Jamming the intra-home communications suppresses alarms to both the occupants and the monitoring company," Lamb says.

Although some alarms use anti-jamming counter measures to prevent someone from blocking signals from sensors to control panels---if they detect a jamming technique, they issue an audible alarm to the occupant and send an automatic transmission to the monitoring company---but Lamb says there are techniques to beat the countermeasures as well, which he'll discuss at his talk.

One of the Australian products that Cesare examined had an additional vulnerability: Not only was he able to intercept unencrypted signals, he could also discover the stored password on the devices---the password a homeowner would use to arm and disarm the whole setup.


The two researchers plan to present their findings separately next month at the Black Hat security conference in Las Vegas. Lamb will also present his research at theDef Con hacker conference. The researchers both focused on home-alarm systems, rather than commercial-grade models used to secure businesses.

The two researchers each used a software-defined radio to intercept and replay communications. Lamb used a USRP N210, which costs about $1,700. For a serious home-burglary ring, this would be a small investment. Lamb says he was able to do a replay attack---copying signals and sending them back to the system to trigger false alarms---from 250 yards away using this device without a direct line of sight to the sensors. Software-defined radios are controlled with software and can be tweaked to monitor different frequencies. With minimal changes to the code in his SDR, Lamb was able to "have my way in all the systems."

But he could also use an RTL-SDR---a device that costs about $10 from Amazon to monitor signals. These devices don't transmit signals, so an attacker wouldn't be able to disable the alarm system. But he could monitor the signals from up to 65 feet away. Because the transmissions contain a unique identifier for each monitored device and event, an attacker could identify when a window or door in a house was opened by an occupant and possibly use it to identify where victims are in the house---for example, when occupants close a bedroom door for the night, indicating they've gone to bed.

"So as people go about their days in their homes, these packets are being broadcast everywhere," he says. "And since they’re unencrypted, adversaries can just sit around and listen in. Suppose you have a small [monitoring] device to chuck in a [rain] gutter. With minimal effort you could tell when someone leaves the house ... and establish habits. I think there’s some value there and some privacy concerns."


Cesare found that some systems used a remote that let homeowner to arm and disarm their alarms without entering a password on a control panel. This data is transmitted in the clear, also via radio frequency, and can be monitored. He found that most of the systems he examined used only a single code. "I captured the codes that were being sent and replayed them and defeated the security of these systems," he says. Cesare notes that the systems could be made more secure by using rolling codes that change, instead of fixed ones, but the manufacturers chose the easier method to implement with their hardware, at the expense of security.

Cesare was also able to physically capture stored passwords a system made by Swann. All he had to do was attach a microcontroller programmer to read data off the EEPROM. Although he says the firmware was protected, preventing him from reading it, the password was exposed, offering another attack vector to disable the alarm.

Cesare points out that commercial-grade systems are likely more secure than the home systems they examined. "In the home-alarm product, there is an expectation that you're not going to have as strong security as a commercial-grade system," he says. But customers still expect at least basic security. As Lamb and Cesare show, that's debatable.

Source: wired.com

26 March 2022

'Big Data' & governments now have access to your heart.


As we should know 'smart' watches have been around for a while, where they have really been taken up by the mainstream 'consumers' for over a decade now.

Their telemetrics have increased significantly over the years, where now even some sensors are gaining certification as medical tools.

Heart rate is child's play now, where Sp02 (saturation of peripheral oxygen), ECG (electrocardiogram) and 'body battery' terms are becoming the new normal.

While one can obtain whatever information one desires with regards to the functioning/accuracy of smart watches from a plethora of successful reviewers on social media, one of the most important aspects is (deliberately?) left out, that being privacy.

It seems that they're just corporate whores, sponsored by the corporations to spruik their wares, but that would just be a conspiracy theory, right?

While one can read the multinational's 'privacy policy' when installing the companion app to their smart watch, and be besotted by their terminology and (alleged) data privacy policy all this is 'smoke and mirrors'.

Do you know why?

They have your data, you are not in control of it's flow, and your personal information must be given in the companion app before the smartwatch is usable to you, otherwise you will not be able to see 'your' data, the data you create/generate.

Can these corporations program the app without obtaining your exact location or email address or phone number?

Of course they can, but the don't want to, or have a secret agreement with agencies not to, as we now live in a surveillance capitalism world within the 5eyes, 9eyes and 14eyes countries.


Example of an app that does not require a login or internet to connect to a smart watch.

As always the humble serf (en masse, of course) can change the ways of corporations, but that would require a little bit of work, and we know how lazy the serfs really are, remembering that their silence is acquiescence.

One way to make that change is by quite simply 'voting' with your wallet, i.e not purchasing the product that the corporation 'requires' your data, and stating that to them.

Not all is lost though, as 'hackers' or rather programmers have been looking into the ins and outs of smart watches and have created apps that do not require the use of the internet to use the smartwatch with your phone in order to access that data that you create.

One such app that is open source which can function with a few brands is called Gadgetbridge, which is only available for the Android operating system smartphone.



We do not recommend the use of any Apple devices if your privacy is a concern, irrespective of their marketing jargon.

There are also other smart watch manufacturers that have companion apps that can be used without a login, but that's a hit and miss scenario.

24 March 2022

Fines Victoria alleged debt, under what lawfully enacted instrument?


This is an actual [template] letter from Fines Victoria from (an alleged) Mr. Duncan Stewart to a 'person', where the 'victim's' details have been obscured.

If you received this letter in your person's name then you may become a victim of fraud by more than one entity, against your person's name.

Let's begin!

Debtor:

  • How did you lawfully incur a debt to 'Fines Victoria' (ABN 68 122 448 122?)?

  • Was there a lawfully issued court order in your person's name and by whom?

  • Was the person issuing the order sitting in office lawfully?

  • Can that person produce the oath taken?

  • Did you get an opportunity to face your accuser?

  • What lawfully issued instrument was used to create the (alleged) debt?


'Dealing' with a fine:

Even at this late stage of the 'game' if you write a letter to Fines Victoria, or Mr. Duncan Stewart more specifically, that you require the matter to be revocated to the court, then you are 'dealing' with the fine.


I may:

The letter states: “I may take one or more actions to recover the amount you owe.”

This means that Mr. Stewart 'may', as opposed to will take action.

I may:-

  1. deduct money from your bank account or wages,

  2. direct VicRoads to suspend your driver licence or vehicle registration,

  3. or charge and sell the land you own.


Now, this is one of the more problematic sections of the letter.

First of all Mr. Stewart needs a lawfully issued instrument to carry out any of those actions, where if one does not exist he has carried out actions beyond his power, where the 'common law' crime of theft will occur if one or more of those actions are carried out.

In point iii). Mr. Stewart states that he 'may' charge and sell the land (eg. where your home is located on) you 'own'.

Mr. Stewart is stating that you factually 'own' this land?

Where is this paperwork that states that you 'own' the land he is coming for?

Mr. Stewart also states the following:

“ If a warrant is issued against you, the Sheriff may wheel clamp your vehicle, take and sell your assets, or arrest you."

Now, this is the most problematic part of the letter thus far.

A sheriff of a state is an officer of the state's Supreme Court.

In the case of Victoria, at this point in time, there is no lawfully appointed sheriff, nor was the previous (alleged) sheriff Mr. Brendan Facey lawfully appointed.

Again, what lawfully issued instrument will allow a person to take your possessions, arrest you or stop your vehicle from moving?


take action”

Writing a letter to Me. Duncan Stewart regarding clarification with regards as to how one has lawfully become a 'debtor' to Fines Victoria is taking action in dealing with the matter.

There are many other aspects of law that must be considered with regards to obtaining a remedy to the letter presented to you.


For example, but not limited to:


  • If there is no lawfully appointed sheriff, then there are no lawful deputies.

  • If a warrant is factually issued it MUST be present to you in its prescribed format, where all the 'checks and balances' are present and not appear as an 'Excel' spreadsheet summary.

  • If you did not appear in court to face your accuser, then this is a breach of the Charter of Rights & Responsibilities, a denial of natural justice.

You must take further action as they will not give you a 'remedy' on a silver plate where they will try to deceive you in the process.

So far there have been no lawfully issued warrants in the state of Victoria, since at least the tenure of Mr. Brendan Facey, as director of Fines Victoria (and not the sheriff) arising from the 'Infringements Court'.

Remembering that judges/magistrates are tort feasors, and not as described under Ch.III of the Constitution.


See other articles:

https://corpau.blogspot.com/2017/05/sheriffs-warrants-do-not-exist-verified.html

https://corpau.blogspot.com/2016/01/what-warrant-form-looks-like.html

The media is paid to distract you

See explanation


Source: The West Report

21 March 2022

Password lengths & how long it takes to crack


A report from cybersecurity firm Hive Systems (via CNBC) reveals how long it can take the average hacker to figure out the passwords that you use to protect your most important online accounts. For example, using numbers alone could allow a hacker to instantly discover your password anywhere from 4 to 11 characters long.

If you use only lowercase letters for a password, you might as well just give the data you're protecting directly to the hackers. Passwords with four to eight characters that are lower case only can be cracked instantly according to Hive while a password consisting of nine lower case letters can be discovered in 10 seconds. If the password requires 10 characters, that time expands to 4 minutes while an 11 character password using nothing but lower case letters can be figured out in two hours.

Advancements in technology help hackers crack passwords faster than just two years ago


Using a mix of lower and uppercase letters, passwords of four through six characters can be cracked instantly according to the study. Passwords comprised of seven characters take only two seconds to discover while passwords with eight, nine, and 10 characters using both lower and upper case letters can be figured out in two minutes, one hour, and three days, respectively. An 11 character password using upper and lower case letters can hold off a hacker for up to five months.


Even if you were to mix in lower case and upper case letters along with numbers, using a password comprised of only four to six characters is not safe at all. And if you were to add symbols to the mix, even a six-letter password could be cracked instantly. The bottom line is that your password needs to be lengthy and adding one extra letter can make a huge difference in keeping your personal data safe.

For example, using lower and upper case letters, numbers, and symbols, a ten-letter password could be solved in five months according to the report. Using the same letters, numbers, and symbols, an 11-character password would take as long as 34 years to crack.

Your online passwords should be no less than eight characters long


Hive suggests that at the minimum, a password used online should contain no fewer than 8 characters using a mix of mix of numbers, uppercase letters, lowercase letters and symbols. Want to have your mind blown? An 18 character password using the aforementioned mix of numbers, letters, and symbols would take up to 438 trillion years to be discovered by the average hacker.

The cybersecurity firm posted a couple of colorful graphs showing how hackers are able to figure out passwords faster now than just two years ago because of advances in technology.

Source: phonearena.com


20 March 2022

Batteries do not make electricity


Batteries, they do not make electricity – they store electricity produced elsewhere, primarily by coal, uranium, natural gas-powered plants, or diesel-fueled generators. So, to say an EV is a zero-emission vehicle is not at all valid.

Also, since forty percent of the electricity generated in the U.S. is from coal-fired plants, it follows that forty percent of the EVs on the road are coal-powered, do you see?"

Einstein's formula, E=MC2, tells us it takes the same amount of energy to move a five-thousand-pound gasoline-driven automobile a mile as it does an electric one. The only question again is what produces the power? To reiterate, it does not come from the battery; the battery is only the storage device, like a gas tank in a car.

There are two orders of batteries, rechargeable, and single-use. The most common single-use batteries are A, AA, AAA, C, D. 9V, and lantern types. Those dry-cell species use zinc, manganese, lithium, silver oxide, or zinc and carbon to store electricity chemically. Please note they all contain toxic, heavy metals.

Rechargeable batteries only differ in their internal materials, usually lithium-ion, nickel-metal oxide, and nickel-cadmium. The United States uses three billion of these two battery types a year, and most are not recycled; they end up in landfills. California is the only state which requires all batteries be recycled. If you throw your small, used batteries in the trash, here is what happens to them.

All batteries are self-discharging. That means even when not in use, they leak tiny amounts of energy. You have likely ruined a flashlight or two from an old, ruptured battery. When a battery runs down and can no longer power a toy or light, you think of it as dead; well, it is not. It continues to leak small amounts of electricity. As the chemicals inside it run out, pressure builds inside the battery's metal casing, and eventually, it cracks. The metals left inside then ooze out. The ooze in your ruined flashlight is toxic, and so is the ooze that will inevitably leak from every battery in a landfill. All batteries eventually rupture; it just takes rechargeable batteries longer to end up in the landfill.

In addition to dry cell batteries, there are also wet cell ones used in automobiles, boats, and motorcycles. The good thing about those is, ninety percent of them are recycled. Unfortunately, we do not yet know how to recycle single-use ones properly.

But that is not half of it. For those of you excited about electric cars and a green revolution, I want you to take a closer look at batteries and also windmills and solar panels. These three technologies share what we call environmentally destructive production costs.

A typical EV battery weighs one thousand pounds, about the size of a travel trunk. It contains twenty-five pounds of lithium, sixty pounds of nickel, 44 pounds of manganese, 30 pounds cobalt, 200 pounds of copper, and 400 pounds of aluminum, steel, and plastic. Inside are over 6,000 individual lithium-ion cells.

It should concern you that all those toxic components come from mining. For instance, to manufacture each EV auto battery, you must process 25,000 pounds of brine for the lithium, 30,000 pounds of ore for the cobalt, 5,000 pounds of ore for the nickel, and 25,000 pounds of ore for copper. All told, you dig up 500,000 pounds of the earth's crust for just - one – battery."

Sixty-eight percent of the world's cobalt, a significant part of a battery, comes from the Congo. Their mines have no pollution controls, and they employ children who die from handling this toxic material. Should we factor in these diseased kids as part of the cost of driving an electric car?"

I'd like to leave you with these thoughts. California is building the largest battery in the world near San Francisco, and they intend to power it from solar panels and windmills. They claim this is the ultimate in being 'green,' but it is not. This construction project is creating an environmental disaster. Let me tell you why.

The main problem with solar arrays is the chemicals needed to process silicate into the silicon used in the panels. To make pure enough silicon requires processing it with hydrochloric acid, sulfuric acid, nitric acid, hydrogen fluoride, trichloroethane, and acetone. In addition, they also need gallium, arsenide, copper-indium-gallium- diselenide, and cadmium-telluride, which also are highly toxic. Silicon dust is a hazard to the workers, and the panels cannot be recycled.

Windmills are the ultimate in embedded costs and environmental destruction. Each weighs 1688 tons (the equivalent of 23 houses) and contains 1300 tons of concrete, 295 tons of steel, 48 tons of iron, 24 tons of fiberglass, and the hard to extract rare earths neodymium, praseodymium, and dysprosium. Each blade weighs 81,000 pounds and will last 15 to 20 years, at which time it must be replaced. We cannot recycle used blades.

There may be a place for these technologies, but you must look beyond the myth of zero emissions.

"Going Green" may sound like the Utopian ideal but when you look at the hidden and embedded costs realistically with an open mind, you can see that Going Green is more destructive to the Earth's environment than meets the eye, for sure.

The solution? Lead simpler lives and use less energy.

Source:supplied

18 March 2022

Air pollution causes ‘huge’ reduction in intelligence, study reveals

Impact of high levels of toxic air ‘is equivalent to having lost a year of education’

Air pollution in China is three times above World Health Organisation limits. Photograph: Kevin Frayer/Getty Images

Air pollution causes a “huge” reduction in intelligence, according to new research, indicating that the damage to society of toxic air is far deeper than the well-known impacts on physical health.

The research was conducted in China but is relevant across the world, with 95% of the global population breathing unsafe air. It found that high pollution levels led to significant drops in test scores in language and arithmetic, with the average impact equivalent to having lost a year of the person’s education.

“Polluted air can cause everyone to reduce their level of education by one year, which is huge,” said Xi Chen at Yale School of Public Health in the US, a member of the research team. “But we know the effect is worse for the elderly, especially those over 64, and for men, and for those with low education. If we calculate [the loss] for those, it may be a few years of education.”

Previous research has found that air pollution harms cognitive performance in students, but this is the first to examine people of all ages and the difference between men and women.

The damage in intelligence was worst for those over 64 years old, with serious consequences, said Chen: “We usually make the most critical financial decisions in old age.” Rebecca Daniels, from the UK public health charity Medact, said: “This report’s findings are extremely worrying.”

Air pollution causes seven million premature deaths a year but the harm to people’s mental abilities is less well known. A recent study found toxic air was linked to “extremely high mortality” in people with mental disorders and earlier work linked it to increased mental illness in children, while another analysis found those living near busy roads had an increased risk of dementia.

The new work, published in the journal Proceedings of the National Academy of Sciences, analysed language and arithmetic tests conducted as part of the China Family Panel Studies on 20,000 people across the nation between 2010 and 2014. The scientists compared the test results with records of nitrogen dioxide and sulphur dioxide pollution.

They found the longer people were exposed to dirty air, the bigger the damage to intelligence, with language ability more harmed than mathematical ability and men more harmed than women. The researchers said this may result from differences in how male and female brains work.

Derrick Ho, at the Hong Kong Polytechnic University, said the impact of air pollution on cognition was important and his group had similar preliminary findings in their work. “It is because high air pollution can potentially be associated with oxidative stress, neuroinflammation, and neurodegeneration of humans,” he said.

Chen said air pollution was most likely to be the cause of the loss of intelligence, rather than simply being a correlation. The study followed the same individuals as air pollution varied from one year to the next, meaning that many other possible causal factors such as genetic differences are automatically accounted for.

The scientists also accounted for the gradual decline in cognition seen as people age and ruled out people being more impatient or uncooperative during tests when pollution was high.

Air pollution was seen to have a short-term impact on intelligence as well and Chen said this could have important consequences, for example for students who have to take crucial entrance exams on polluted days.

“But there is no shortcut to solve this issue,” he said. “Governments really need to take concrete measures to reduce air pollution. That may benefit human capital, which is one of the most important driving forces of economic growth.” In China, air pollution is declining but remains three times above World Health Organisation (WHO) limits.

According to the WHO, 20 of the world’s most polluted cities are in developing countries. China, home to several of those cities, has been engaged in a “war against pollution” for the past five years.

A migrant worker listens to the radio on his tricycle cart. Photograph: Andy Wong/AP

The results would apply around the world, Chen added. The damage to intelligence was likely to be incremental, he said, with a 1mg rise in pollution over three years equivalent to losing more than a month of education. Small pollution particles are known to be especially damaging. “That is the same wherever you live. As human beings we have more in common than is different.”

Aarash Saleh, a registrar in respiratory medicine in the UK and part of the Doctors Against Diesel campaign, said: “This study adds to the concerning bank of evidence showing that exposure to air pollution can worsen our cognitive function. Road traffic is the biggest contributor to air pollution in residential areas and the government needs to act urgently to remove heavily-polluting vehicles from our roads.”

Daniels said: “The UK’s air is illegally polluted and is harming people’s health every day. Current policies are not up to the scale of the challenge: government must commit to bringing air pollution below legal limits as soon as possible.”

Source: theguardian.com



16 March 2022

Ukraine on Fire Google's censorship


Once people get a hold of something that does not fit the 'corporate' agenda, and draw attention to it, the technocrats swing into action censoring it.

The latest being a documentary film by Oliver Stone from 2016 called Ukraine on Fire.

Google have already taken it down from YouTube a few times.

Google even knows that people have put it up elsewhere.

'Normally' when one types in a website name followed by the searched variable, Google points to it, but in this case, no mention of that website anywhere.

In any event, here is the link to the 2.1GB download that is active at the time of this post:

https://www.transfernow.net/en/dltransfer?utm_source=20220315mFEMnmSb

14 March 2022

No Jab No Social Security?

Social Security is a polarising topic for many Australians at the best of times, where these days it can be more contentious.

Once it was called the Department of Social Security, then Centrelink and now Services Australia.

What's in an name change, right?

Well, a lot more than what people are led to believe, but that's another topic altogether.

We've obtained information from within, with regards as to what the #ScottyFromMarketing administration is planning to enact in approximately 5 months from now, that being August 2022.

Many people should be aware that in pop culture, the (United States) constitution is mentioned or rather emphasised as lot, when it comes to the actions of authorities against the citizen population.

In Australia, the story could not be more different, where even if one actually refers to the legal founding document of the colony Australia, then one gets ridiculed by e.g. police, or even other administration staff.

People should be aware now of the 'tricks', enticements, blackmail and most importantly unlawful 'requests' used on persons in order for them to succumb to a medical service.

There's No Jab No Play, No Jab No Job, No Jab No Pay catch phrases that people are being forced into.

What the federal government is planning to employ in August is that a person will not receive social welfare payments unless that person has succumbed to a particular medical service.

There are a fair few problems with that.

One is that Section 51 (xxiiA) of that 'law' called the Constitution, forbids the Australian Government from providing medical and dental services in such a way as to oblige persons to accept those services.

The so called medical service that one must accept cannot be called what it is, as it does not provide the functions of what it's referred to as.

Proof does not exist that the follow up medical services that have been cleverly labelled as 'up to date' are factually effective.

Social modelling shows that when the safety net of welfare is taken away from the general population, criminal activity increases.

Therefore if/when this is enacted the people in government want more criminal activity to occur.

The authorities e.g. the police within the continent, in Western Australia and across the Tasman, in New Zealand are challenging the so called mandates and are having them nullified, whereas the general population must succumb to that unlawful request.

The general population do not comprehend the reality they live in on this continent.

While people are told that they live in a 'democracy' here, they certainly do not live in a 'free' society, as alleged elsewhere.

The actions are what's important, as opposed to what is being 'advertised' to you.

Australia, still being a colony enforces 'penal colony policies' where now during the events of the past two years have put the government into a totalitarian régime.

The very thing that the police have fought for, the general population is being beaten and assaulted for.


Grandmother being assaulted by Victoria Police during a peaceful Melbourne march.

Make no mistake Australia is a police state.


13 March 2022

Can The FBI Hack Into Private Signal Messages On A Locked iPhone? Evidence Indicates Yes


The FBI appears to have a tool that can access Signal messages, even if a device is locked. (Photo Illustration by Rafael Henrique/SOPA Images/LightRocket via Getty Images) SOPA Images/LightRocket via Getty Images 

Signal has become the de facto king of secure messaging apps of late, stealing users from WhatsApp and gathering millions of others looking for private forms of communication. That means the police and governments will be wanting, more than ever, to ensure they have forensic techniques to access Signal messages. Court documents obtained by Forbes not only attest to that desire, but indicate the FBI has a way of accessing Signal texts even if they’re behind the lockscreen of an iPhone.

The clues came via Seamus Hughes at the Program on Extremism at the George Washington University in court documents containing screenshots of Signal messages between men accused, in 2020, of running a gun trafficking operation in New York. (The suspects have not yet entered a plea and remain innocent until proven guilty). In the Signal chats obtained from one of their phones, they discuss not just weapons trades but attempted murder too, according to documents filed by the Justice Department. There’s also some metadata in the screenshots, which indicates not only that Signal had been decrypted on the phone, but that the extraction was done in “partial AFU.” That latter acronym stands for “after first unlock” and describes an iPhone in a certain state: an iPhone that is locked but that has been unlocked once and not turned off. An iPhone in this state is more susceptible to having data inside extracted because encryption keys are stored in memory. Any hackers or hacking devices with the right iPhone vulnerabilities could then piece together keys and start unlocking private data inside the device.

Signal messages accessed in an investigation into a gun trafficking scheme, from a government filing in the case. Metadata between the messages indicates the phone was locked. Screenshot from Department of Justice file 

For police to access private Signal messages from an iPhone, there are some other caveats besides a device needing to be in AFU mode. The iPhone in question appears to be either an iPhone 11 (whether Pro or Max) or a second generation iPhone SE. It’s unclear if the police can access private data on an iPhone 12. It’s also not clear what software version was on the device. Newer iOS models may have better security. Apple declined to comment, but pointed Forbes to its response to previous research regarding searches of iPhones in AFU mode, in which it noted they required physical access and were costly to do.

A Signal spokesperson said: “If someone is in physical possession of a device and can exploit an unpatched Apple or Google operating system vulnerability in order to partially or fully bypass the lock screen on Android or iOS, they can then interact with the device as though they are its owner.

“Keeping devices up-to-date and choosing a strong lock screen passcode can help protect information if a device is lost or stolen.”

Counsel for the defendant in the New York case didn’t respond to messages. The Justice Department said it couldn’t comment.

GrayKey vs. Cellebrite

Forensic exploitation of devices affects any encrypted communications app, from WhatsApp to Wickr, not just Signal. What is apparent is that the government has a tool that can bypass encryption to get into what most people would assume are private messages. The question remains: What is that tool? It’s likely to be one of two popular iPhone forensics tools used by the FBI: the GrayKey or the Cellebrite UFED.

GrayKey, a tool created by Atlanta-based startup Grayshift, has been an increasingly popular choice for the FBI. The agency has spent hundreds of thousands of dollars on acquiring the devices, which start in price from $9,995. When Forbes obtained a leaked recording of Grayshift CEO David Miles talking in mid-2019, he said that his company’s tech could get “almost everything” on an iPhone in AFU mode.

Vladimir Katalov, founder of Russian forensics company ElcomSoft, said he believed GrayKey was the tool in use in the New York case. “It uses some very advanced approach using hardware vulnerabilities,” he hypothesized. Grayshift hadn’t responded to a request for comment at the time of publication.

Cellebrite, an established Israeli forensics tech provider, has long served American law enforcement, as well as global police agencies. A spokesperson said it was Cellebrite policy “not to comment on specific customers or uses of our technology,” but added that “law enforcement agencies are seeing a rapid rise in the adoption of highly encrypted apps like Signal by criminals who wish to communicate, send attachments and make illegal deals they want to keep discrete and out of sight from law enforcement.”

In December, Cellebrite indicated it had developed “advanced techniques” to bypass Signal encryption, though Signal issued a statement lambasting not just the company but media reports that had repeated Cellebrite’s claims. In a blog post, Signal said all Cellebrite had done was “parse Signal on an Android device they physically have with the screen unlocked.

“This is a situation where someone is holding an unlocked phone in their hands and could simply open the app to look at the messages in it. Their post was about doing the same thing programmatically (which is equally simple).”

When Signal cofounder Moxie Marlinspike commented on the Cellebrite claims in December, he called it “amateur hour.” Whatever tools the FBI used in the New York case, they’re far from amateur.

Source: forbes.com