Advertisement
UK markets close in 2 minutes
  • FTSE 100

    8,043.40
    +19.53 (+0.24%)
     
  • FTSE 250

    19,782.17
    +182.78 (+0.93%)
     
  • AIM

    755.45
    +6.27 (+0.84%)
     
  • GBP/EUR

    1.1622
    +0.0033 (+0.29%)
     
  • GBP/USD

    1.2440
    +0.0089 (+0.72%)
     
  • Bitcoin GBP

    53,660.21
    +743.22 (+1.40%)
     
  • CMC Crypto 200

    1,437.11
    +22.35 (+1.58%)
     
  • S&P 500

    5,064.88
    +54.28 (+1.08%)
     
  • DOW

    38,463.69
    +223.71 (+0.59%)
     
  • CRUDE OIL

    82.74
    +0.84 (+1.03%)
     
  • GOLD FUTURES

    2,334.60
    -11.80 (-0.50%)
     
  • NIKKEI 225

    37,552.16
    +113.55 (+0.30%)
     
  • HANG SENG

    16,828.93
    +317.24 (+1.92%)
     
  • DAX

    18,121.59
    +260.79 (+1.46%)
     
  • CAC 40

    8,101.91
    +61.55 (+0.77%)
     

Encrypted chat app Signal alleges flaws in Cellebrite equipment

FILE PHOTO: USB device is attached to Cellebrite UFED TOUCH, a device for the data extraction from mobile device such as mobile phone or smart phone, as it was demonstrated by Japanese electronics maker Sun Corp. during a photo opportunity in Tokyo

WASHINGTON (Reuters) - Encrypted chat app Signal suggested in a blog post published on Wednesday that products sold to law enforcement from Israeli surveillance provider Cellebrite can easily be sabotaged.

Cellebrite DI Ltd, which specializes in helping law enforcement and intelligence agencies copy call logs, texts, photos and other data off of smartphones, has repeatedly come under fire for past sales to authoritarian governments, including Russia and China.

Signal, a privacy-focused app eager to show the lengths it goes to protect users' conversations, clashed with Cellebrite last year when the Israeli company said its equipment was upgraded to allow law enforcement to scoop up Signal messages from devices in their possession.

Signal creator and CEO Moxie Marlinspike said in his blog post on Wednesday he had come into possession of a bag of Cellebrite equipment and examined the gear inside.

ADVERTISEMENT

He was "surprised to find that very little care seems to have been given to Cellebrite's own software security," Marlinspike said, noting it would be easy to add a specially crafted file onto a phone that would derail Cellebrite's functionality.

In a statement, Cellebrite did not directly address Marlinspike's claim but said that the company's employees "continually audit and update our software in order to equip our customers with the best digital intelligence solutions available."

Elsewhere in his blog post, Marlinspike alleged he had found snippets of code from Apple Inc inside Cellebrite's software, something he said "might present a legal risk for Cellebrite and its users" if it was done without authorization.

Apple did not immediately respond to a request for comment.

Signal's allegations come as Cellebrite prepares to go public through a merger with a blank-check firm, valuing the equity of the combined company at around $2.4 billion.

(Reporting by Raphael Satter; Editing by Richard Chang and Edwina Gibbs)