Field Notes

source

Listening In

Cybersecurity in an Insecure Age

Susan Landau’s Listening In: Cybersecurity in an Insecure Age (Yale University Press, 2017) is a policy-and-technology study of law-enforcement access to encrypted communications, by a Tufts cybersecurity-policy professor with a long record in the crypto-wars debates. The saved copy is the EPUB edition. Chapter 5 covers the exploit market and the phone-forensics industry, including the San Bernardino iPhone case.

What it is evidence for

Pages 142–147, as cited in Cellebrite, describe the commercial phone-extraction business: Cellebrite’s origin in phone-to-phone data transfer, its capabilities deriving “from a combination of close relationships with phone manufacturers” (who share designs months before launch), “highly talented technologists” reverse-engineering devices, and tools “quite similar to iOS ‘jail breaking’ tools available over the Internet.” The same pages cover zero-day pricing (thousands to seven figures, indexed to platform prevalence and exclusivity), the RAND stockpile-versus-disclose findings, and Zdziarski’s criticism of “push-and-drool” tooling — investigators pressing a button without understanding the tool’s limitations. The vault’s citation of pp. 142–147 for these claims was verified against the text on import: the page anchors and the index entry (“zero-day vulnerabilities, 142–43, 147”) match the cited propositions.

Limitations

Published in 2017, the book predates Cellebrite Premium, Inseyets, the Corellium acquisition, and the modern secure-element landscape; use it for the industry’s structure and incentives, not for current capabilities. Landau writes as a policy advocate in the encryption-debate tradition; her descriptive claims about the industry are corroborated by the leaked matrices and vendor documentation the vault holds, but her normative framing is her own.

Placement

Cited by Cellebrite for the capability-derivation claims and the RAND zero-day findings; relevant background for Demystifying phone unlocking tools and Reliability of mobile forensic extraction as evidence.

Built on 1 source (1 external).

Working out connections…