Still an interesting read:
back
2 comments
Ouch, that's pretty nasty.
Also, I couldn't help but be amused by cheekiness:
"By a truly unbelievable coincidence, I was recently out for a walk when I saw a small package fall off a truck ahead of me. As I got closer, the dull enterprise typeface slowly came into focus: Cellebrite. Inside, we found the latest versions of the Cellebrite software, a hardware dongle designed to prevent piracy (tells you something about their customers I guess!), and a bizarrely large number of cable adapters."
This was amazing and made me even more happy to use Signal. Incredible read
If you think Cellebrite can't extract all your Signal messages you are very much mistaken.
If the messages are encrypted locally (an option on iOS), and Celebrite fails to brute force your login code, then yes, they cannot extract Signal messages.
"bypassing" the screenlock is a selling point on the product page, thou
Keep in mind the default and what most people stick to is a simple numeric passcode, which can easily be bruteforced because you can just iterate through all the numbers. If the replay protection doesn't work they will be able to get in, its just a matter of time. If everything is working as it should and you use a proper alphanumeric/symbol passcode, I think thats less feasible if not downright impossible.
i'd say that the amount of ppl that have this "delete data after 10 failures" feature enabled is vanishingly small, hence every passcode can be bruteforced
Login code is used to encrypt this data, so merely "bypassing" wouldn't help. It needs to be brute forced.
if i can try all the combinations i have indeed bypassed the need to know the correct one