logoalt Hacker News

ssl-3 • today at 12:04 AM • 0 replies • view on HN

It's either that, or maintain a database of trusted USB devices...which seems iffy, at best.

And by that I mean, using the database itself is simple. But when it exists, then a list of targets for an attacker to emulate also exists.

Those boys at Cellebrite aren't dummies, at all, and they've been doing this stuff for quite a long time. They're a formidable opponent.

We used to use their kit to clone personal data between very different devices back in the dumb phone days. They were the only ones to get it right out of a sea of others that were also evaluated.