News

Decrypt iOS Signal App Data with Belkasoft Evidence Center

Signal is widely considered one of the most secure messaging services. Even Edward Snowden called Signal his favorite messaging app.

While the exact figures for Signal's user base are not publicly known, reports indicate that the app recorded 10 million downloads on Google's Play Market in 2020, and another 40 percent of the app's users are on iOS. Signal's rivals include messaging apps with larger user databases (such as WhatApp, Telegram) and smaller niche messaging apps (such as Wickr and Dust).

With the latest investments from WhatsApp co-founder Brian Acton, Signal continues to gain momentum and is becoming more popular among security-conscious users, activists, journalists, and lawyers.

The app is even recommended for use in government spaces. In February 2020, the European Commission recommended its staff switch to Signal to improve the security of their communications. By 2020, more than 30% of US media outlets, including the New York Times, Washington Post, and Wall Street Journal, will use Signal to receive new entries.

The core idea behind Signal is to provide users with the highest possible levels of anti-surveillance capabilities. Unfortunately, lawbreakers can also use a secure app as an entry point for criminal activity.

According to EUROPOL's annual report “Assessing the threat of organized crime on the Internet”, the following crimes could be perpetrated through instant messaging: online solicitation of children for sexual purposes, terrorist acts launched using an application as a communication point and dark web markets.

Instant messaging (IM) applications have the potential to become a rich source of evidence in criminal investigations. Furthermore, when it comes to these types of applications, the information that can be collected in the context of an investigation goes beyond text messages.

Why is the Signal app so difficult to crack?
Digital forensic investigators often encounter obstacles when trying to extract evidence from mobile devices. Specific challenges, such as different operating systems on smartphones, password recovery mishaps, and other issues, define mobile forensics.

The Signal app is no exception. When using this mobile application as a source of evidence, investigators should try to understand its key security features.

The Signal app on iOS uses a keychain to store the decryption key, making it difficult to decrypt its databases. It is not an easy task to remove a keychain, because it means that you have to access an iOS device with a method that allows you to acquire the so-called 'full file system' (often abbreviated as FFS), or to be able to download the keychain from iCloud.

What is a Keychain?
Keychain is the password manager that Apple builds into its devices to store user passwords, credit card data, Wi-Fi login data, and a host of other important data.

Keychain is the most popular password manager used on iPhones, making keychain extraction an incredibly important and useful capability for any digital forensics investigator or computer security investigator.

The problem here is that there is no official way to recover keychain data. It is not extracted as part of the iTunes backup; There is no Apple-approved way to access it.

How to extract data from iOS Signal with Belkasoft X?
1. Extracting iTunes or iCloud backups won't help
When investigating Signal conversation history on iPhones, the first idea that comes to mind is to check backups. While the idea might work for some apps like WhatsApp (if the user configured the app to store conversation histories in iCloud and iCloud Drive for iOS backups), it will never work for Signal.

Signal simply does not save chat histories and does not save its encryption keys in local backups. Users cannot tell the Signal app to backup their conversations, because Signal developers deliberately left out the required features (for security reasons). If nothing is stored in the cloud, iCloud Extract can never be used to get data from Signal.

2. Full FFS file system extraction will work!
Since cloud backups and extraction will not work, the other technique requires a complete extraction of the file system.

Belkasoft

Using Belkasoft

Identify the iPhone model from which you intend to extract evidence
For iPhone models from iPhone 5S to iPhone in Belkasoft X
For iOS versions 10.3-14.3 and 15.0-15.1.1, you can use agent-based acquisition functions (although we support later versions of iOS for this method, we will not extract the keychain for them)
For other iPhone/iPad models or iOS versions, you will need to use a relevant jailbreak (if one exists)
Open Belkasoft X on your PC
Connect an iPhone to your PC with an original Apple cable via the USB 3.0 port

Choose checkm8-based or agent-based acquisition method in Belkasoft
For checkm8: Enter recovery mode and then enable DFU mode on iOS device (see instructions provided by Belkasoft X)
The iPhone (or iPad) and Belkasoft X will begin to communicate. The product will apply the corresponding exploit. While acquiring a complete file system image, Belkasoft X will also extract the file from the keychain automatically
The result of the acquisition is a .tar file, which contains in particular Signal database files and a keychain.
Finally, when the image acquisition process is completed, the device will be rebooted (for checkm8) or the agent will be removed. In any case, there will be no traces of an exploit left on the device.
Now you can start analyzing the acquired image.
During the analysis stage, Belkasoft X will extract the Signal encryption key from the keychain and automatically decrypt the Signal data. After extracting the entire iOS file system, the ‘Passwords’ node will appear in the Artifacts window:

Keychain file passwords are stored as a token or as an original character set in the Password node.

The data recovered from Signal contains chat history, calls, videos, audio messages, shared images and links, and geolocation data, all of which are included in the Signal messaging node. The latter is located in the Chats node in Artifacts:

Third Party Extraction Decryption
Another frequently asked question is “How do I decrypt Signal data if I have a third-party extraction” (say, GrayKey or Cellebrite). Since there is no standard way to maintain a keychain in a forensic extraction, the keychain value will not be automatically obtained from a third-party image. However, Belkasoft X allows you to specify the Signal keychain value if it is not found automatically.

Go to your third party image, find the keychain file. Look for '/private/var/Keychains/keychain-2' or around, although the particular path within an image depends of course on the provider.
Find the signal key that has the ID 'org.whispersystems.signal'
The required value will look like this:
ZThlYmE4MTQzNTU2OWU2MTZiZWNkMzIyMGEwY2RiZjY5YjQ5NDhiMzU4MDU0NjUzMzQxYzBhMzRkYmUxOGIwZTAxNGZhNWEyOTUzZjFkODNjMGUyOTI4MGMxM2UxNDk4

This is a base64 encoded value that, decoded, can look like this:

e8eba81435569e616becd3220a0cdbf69b4948b358054653341c0a34dbe18b0e014fa5a2953f1d83c0e29280c13e1498

Belkasoft X will require the value in base64. In the Belkasoft X Tasks window, locate the signal decryption task and click the “Enter missing data” button there:

In the opened window, paste the copied keychain value.
If everything is done correctly, the signal data will be decrypted and displayed in the Belkasoft X Artifacts window.
Conclusion
Signal is an incredibly secure messenger, which is quickly gaining momentum thanks to its impressive anti-surveillance capabilities. For this reason, digital forensic investigators should strive to work with Signal as an evidentiary point.

Signal chat history is not stored in the standard iTunes backup. Your database on an iOS device is well encrypted using a key stored in the keychain. That's why you can't decrypt Signal using an iTunes backup or even if you have a Signal database without a decryption key from a keychain.

To successfully crack the iOS Signal app, you need a complete file system image and a keychain. Methods to extract both items vary depending on different iPhone/iPad models and installed iOS versions and include checkm8, agent-based and jailbreak-based acquisitions.

Belkasoft X supports all the methods mentioned above and if an image is acquired with the help of this product, the tool will automatically decrypt the Signal data. For third-party extractions, Belkasoft X allows you to enter a Signal decryption key which you must manually locate in a keychain file and copy to the product.

read it inBelkasoft.com