Transcription
Why is Israeli surveillance technology being used to hack your phone? Let's find out.
I'm Nick Hannah, criminal lawyer, and welcome to the first episode of The What and the Why. On this channel, I'll break down some of the most important criminal justice issues that you won't hear about in the mainstream media.
Today, I'm going to take a deep dive into the Israeli digital intelligence giant, Celebrite, and explain how its technology is being used on a mass scale by police and government agencies in Australia and around the world. Now, you might be asking, "Okay, is this just about the cops getting into the phones of criminals? If so, what's the big deal?" Well, in this video, I'm going to explain why there's a whole lot more to the story and how the use of Celbrite technology in Australia raises serious privacy concerns for all of us.
I'm going to start by looking at the darker side of Celebrite that most people don't know about. The company's extremely close ties with the Israeli military, particularly the infamous cyber warfare unit 8200, as well as the assistance it's provided to repressive regimes around the globe. Then I'm going to look at how insanely advanced and far-reaching Celebrite surveillance capabilities are and how it can download all of your phone and social media data as well as a ton of information about you that you wouldn't even know exists. After that, I'm going to explain how Celbrite products are being used by law enforcement and other government agencies on a large scale with very few restrictions and no real oversight. I'll show how it's not just being used to download the phones of criminals, but also victims and witnesses of crime and countless innocent people. Finally, I'm going to talk about what happens with all of this highly sensitive data that's being downloaded from our phones. In doing so, I'll show you why there's a real risk that Celbrite may be able to access our data and why that's something we should all be worried about.
So, let's start by talking a bit about the company itself. Celbrite is an Israeli surveillance company that sells software for the collection and analysis of digital data. It's best known for its ability to hack mobile phones, but that's just one of many products that it offers. Celbrite has thousands of clients across the globe, including law enforcement and spy agencies, foreign militaries, and private corporations. Celbrite's headquarters are located just outside Tel Aiv, but it has offices around the world, including here in Australia.
On its website, the company says that its core values are personal privacy, public safety, transparency, and respect for individual rights. But there's some good reasons to doubt this claim. For starters, Celebrite has very close ties with the Israeli military, which is not exactly known for its respect for human rights. Until recently, the company has been run by its long-term CEO, Yosi Carmel, who was formerly a Lieutenant Colonel in the elite Israeli paratrooper brigade and after that held a senior position in the Israeli Ministry of Defense. In 2021, Carmel admitted that most celebrate employees come from the infamous Israeli unit 8200 or similar units.
Now, to understand why that's so important, we need to talk a bit about Unit 8200. Unit 8200 is the main intelligence and cyber warfare unit of the Israeli military. Historically, its primary goal has been the mass surveillance of Palestinians and the populations in neighboring Arab countries. To give you an idea of what unit 8200 gets up to, in 2014, a few dozen reserveists from the unit published an open letter to the Israeli government in which they refused to continue their service due to the unit's mass surveillance and persecution of innocent Palestinians. In another open letter published at around the same time, a Unit 8200 whistleblower described how the unit collects highly sensitive personal information from Palestinian civilian, like if they're a closet homosexual, they're cheating on their wife, or they're in need of urgent medical treatment, and then use that information to blackmail them into becoming informants.
Here is one of the 8200 whistleblowers being interviewed in 2014. The problem is that the goal of uh what the unit does in regards with uh Palestinians is not just uh self-defense. It's upholding a military regime. It means to oppress the population. It means to weaken the political system of the Palestinians so that they can't improve their situation so that the military regime continues.
Over time, Unit 8200's capabilities have expanded and is now considered to be one of the foremost intelligence agencies in the world. It operates out of the Euras in the Neg Desert, one of the most powerful intelligence gathering sites on the planet. From there, it monitors phone calls and electronic communications throughout the Middle East, Europe, Africa, and Asia. It is also reported to run covert listening posts in Israeli embassies abroad and is known to cooperate closely with the USA's National Security Agency.
So, what does unit 8200 do with all of this data that it collects? Well, much of that is of course kept under wraps, but one of the more chilling examples that was exposed by an Israeli media outlet last year is the artificial intelligence targeting system known as Lavender. Lavender, which was developed by Unit 8200, is an AI system that processes all of the phone and other data the unit has collected and then uses it to create lists of people in Gaza to be killed by the Israeli military. Israeli sources have disclosed how there is minimal human oversight of the system and more concerningly how the Israeli army pre-authorizes allowances for the estimated number of civilians who can be killed in each strike.
As is explained in this video published by Vox. >> Sources told reporters that for every junior Hamas operative that Lavender marked it was permissible to kill up to 15 or 20 civilians, but also that for some targets the number of permissible civilian casualties was as high as 300.
The cyber and other military operations that 8200 has been involved in have not just been directed against Palestinians, but also foreign states including Syria, Lebanon, and Iran. For example, 8200 played a key role in the planning of Israel's unilateral military strikes against Iran last month, which left hundreds of Iranians dead. Unit 8200 is also believed to have played a key role in the pager attacks in Lebanon last September when Israel simultaneously detonated thousands of explosive devices it had concealed inside pages, killing and maming thousands of Lebanese citizens, both Hezbollah fighters and civilians, including numerous children. The attack was widely condemned by human rights experts as violating international law. And even former CIA director Leon Petta described it as a form of terrorism. >> Is it terrorism? >> I don't think there's any question that it's a form of terrorism.
I was in South Beirut during the pager attack and I remember the chaos on the streets and the feeling of terror that swept across the city. [Music]
Now, you might think that with 8200's track record, Celebrite might try to distance itself from the unit for PR reasons. Well, that's definitely not the case. In fact, Celebrite openly promotes the fact that it's made up of unit 8200 veterans as one of its key selling points. For example, as you can see in this presentation for investors, Celebrite boasts about having worldclass talent from the unit and that this gives the company a competitive advantage by generating unmatched capabilities. And it's not just low-level employees who are ex-Israeli intelligence, but many people who occupy senior positions in the company. For example, the company's long-standing CFO, Donna Gerner, is a Unit 8200 veteran, a fact which she openly discloses on her LinkedIn page. Gerner is also a director of Celbrite's local branch, Celebrite Australia, which is based in Canra.
Now, this relationship between Celebrite and former 8200 members has been the subject of some excellent reporting, including by the Jewish Australian journalist Anthony Loenstein, who authored a very important book called The Palestine Laboratory. But what hasn't been talked about a lot is the ongoing relationship between Celite and the Israeli Army. Because you might be thinking, "Okay, sure, Celebrate is full of former 8200 hackers who have a shady past, but these guys might have put that chapter behind them, and now they're just living like normal civilians or tech bros." Well, it's important to understand that like all soldiers who have served in the Israeli military, 8,200 veterans must return for compulsory service as reserves each year. The length of this annual service duty used to be up to 3 weeks, but it's been significantly extended during Israel's war on Gaza over the past 20 months. So, there is this ongoing exchange of information between the unit's current and former members, which as Forbes reported in a glowing article about Unit 8200 in 2015, allows the unit's veterans to get a peak into the latest technology being developed by their younger successes. And let's be clear about what kind of technology this is. It's technology that is used for mass surveillance in the West Bank, mass killing in Gaza, and for cyber warfare in neighboring countries.
Beyond this overlap between the company and Israeli intelligence personnel, Celebrite appears to be actively supporting the Israeli army as it carries out its brutal offensive in Gaza, which is considered to be a genocide by most human rights organizations and genocide scholars. In the early days of Israel's military onslaught in Gaza, Celebrite admitted on Instagram how proud it is to stand beside its IDF soldiers and how they dispatch vital equipment, food, mobile charges, and clothing to the front lines. There are two photos from this post that I want to show you. In the first shot, you can see soldiers with a box of goodies gifted by Celebrite. In the second shot, you can see armed soldiers who either appear to be in Gaza or getting ready to invade Gaza wearing t-shirts donated by Celbrite emlazed with the company's slogan doing good. Yes, doing good.
In November 2023, when Israel's ground offensive in Gaza was in full effect, then CEO Yossi Carmal said that those on the front line are risking their lives for the country. Our mission is to take care of economic security during a war and the day after. More importantly though, he went on to say that Celbrite had done a lot to assist Israeli law enforcement and special operations in times of crisis, but said he couldn't discuss this in detail.
Now, the precise nature of Celbright's involvement in Gaza is of course shrouded in secrecy. We know that the Israeli army is using it to crack the phones of Palestinians it takes captive in the besieged enclave. And it's also been reported in the Israeli military that celebrates received funding from the Pentagon to develop a product to identify, map, and expose what it describes as Hamas terrorists, which as we've seen over the last 20 months, can mean anyone from journalists to doctors, bakers, and even school children. But beyond this, we're really in the dark about Celebrite's role in Gaza.
Apart from Gaza, CBrite also plays an important role in the military occupation of the West Bank. For example, the Israeli army uses the company's software to hack the phones that it seizes not only from Palestinians, but also countless foreign peace activists and journalists there. This use of celebrate technology is of course unlawful in circumstances where Israel's occupation of the Palestinian territories itself is unlawful, as was recently confirmed by the International Court of Justice in its advisory opinion handed down in July last year.
Beyond Palestine, human rights groups have long accused Celebrite of aiding various authoritarian governments around the world. In 2016, it was revealed that the Bahraini regime, which is one of the worst human rights records in the world, was a client of Celebrite and used its technology to download the phone of a blogger who had reportedly been arrested and tortured simply for speaking out against human rights abuses there. In 2017, celebrate was used against Reuters journalists in Myanmar who were charged with publishing evidence of a massacre of Rahinga people. In 2021, the Israeli media outlet Harets, published an article claiming that Celbrite was being used by the Bangladeshi paramilitary unit, the Rapid Action Battalion, which is accused of extrajudicial killings and torture of hundreds of civilians. In the same year, the Committee to Protect Journalists documented the use of Celebrite in Botswana to examine the phones of journalists who had been arrested in relation to Facebook posts about CO 19. And these are just four of countless examples of Celebrite being allegedly used by regimes with appalling human rights records. Other notable Celebrite clients include the Kingdom of Saudi Arabia, the UAE, and Georgia.
In the West, Celebrite products were also used in ways that many would find very controversial. For example, in the USA, some universities have been accused of using Celebrite technology as part of their crackdown on students engaging in peaceful pro Palestine activities on campus. Celebrate is also used extensively by US immigration and customs enforcement or ICE, which perhaps explained why the company's share price hit an all-time high on the day after the election victory of Donald Trump, who had campaigned on an aggressively anti-immigration platform. And this is nothing new really as Celebrite has been openly promoting its tools to western governments for use against asylum seekers since at least 2019.
So I think that's enough for you to get an idea about the type of company that Celebrite is. Now I want to talk a bit about what Celebrite technology can do. Celebrate offers a range of products for accessing and analyzing digital data. It's best known for its universal forensic extraction device or UID which is the product used to access electronic devices and download their data. EUID can be used on a range of devices, including tablets, computers, USB drives, and SIM cards, but it's most commonly used on mobile phones, and that's what I'm going to focus on in this video.
UID's most important feature is its ability to get into locked phones, even if they're passcode protected. Once HUD has cracked the passcode on your phone, it can start downloading the data on it. Now, what kind of data does it download? Well, the short answer is everything. all of your text messages, emails, photos, videos, call logs, contacts, Google searches, map searches, health data, everything. And when I say text messages, I'm not just talking about SMS. You downloads the chats that are stored on your phone from all of your messaging apps, even the encrypted ones like WhatsApp, Signal, Telegram, and Threma. And it doesn't just get the messages you've got stored on your phone, but can often also recover messages you've deleted.
Importantly, you also downloads all of the metadata on your phone, which is the data about the data. Let's take your camera roll for example. Every phone and video on your phone contains a lot of additional info like the date and time it was taken, whether it was taken with your phone or someone else's, and if you've got your location services turned on, which most people do, your GPS coordinates at the time it was taken. Location data is particularly important because most of your apps save this data and so your phone can usually show where you are at all times.
One of the newer and lesserk known features of EUD is its ability to download the hidden data on your phone that you can't see yourself and you probably didn't even know was saved on your phone. For example, every iPhone that uses iOS 15 or later stores what's called biome files, which can reveal an insane amount of info about your everyday life. There's more than 130 categories of biome files, but some of the main ones include the histories of every app you've used at any given time, every Wi-Fi network and Bluetooth device you've connected to, every time your phone was locked and unlocked, every time you've put it in airplane mode, every notification you've received, and all of your Siri usage.
Now, some of this data might seem pretty trivial, but it can actually reveal extremely important info about you and your daily activities. To illustrate the point, let's look at the recent high-profile murder retrial of Karen Reed in the US. Karen Reed was accused of murdering her boyfriend, and one of the main factual issues in dispute at the trial was where her boyfriend had died. The prosecution argued that Miss Reed had killed her boyfriend outside the home of one of his mates, whereas her lawyers had claimed he could have been killed inside the house. Relevantly, the death happened in the middle of Windsor in Massachusetts. And the prosecution used evidence of the low temperature of the battery of the deceased's iPhone, which had been downloaded by EUD, to support their theory that he could have been outside in the cold when he was killed.
Here is CBrite expert Ian Whiffin giving evidence at the trial. Is there another subject that you looked at that you analyzed in order to reach a conclusion about the time and location of John O'Keefe's cell phone over the night of January 29, 2022? >> Uh yes, the next one is battery temperature. >> Can you explain a little bit background on this before you start the slides? Uh so again we we have a temperature sensor built in within the phone monitoring for uh if the the battery temperature increases too high and becomes a danger or if the temperature gets too low and becomes an issue. Uh so it constantly monitors uh the temperature of the battery and records that information in the knowledge C database.
This same celebrate expert gave evidence at the trial about how iPhones also record every time they are in pocket state, which is basically when the phone's cameras are blocked, usually because it's in your pocket. The prosecution used this pocket state data in combination with the location data and battery temperature to try to show precisely where Mr. O'Keefe was at the time of his death.
So, it's pretty crazy when you think about all of the kinds of data that can be downloaded using EUID. And it's even crazier to think that this is just one of several products that Celbrite offers. Now, there's not enough time to go through all of Celibbrite's other products in as much detail, but I just want to give you an overview of some of the main ones.
You cloud is like, but for your data that's stored in the cloud. This commonly includes all of your social media data, your phone backups, and your cloud storage accounts like Apple iCloud and Dropbox. It also includes sensitive data that some apps store on the cloud instead of on your phone like all of your Uber activity and your online purchases.
Celebrate Endpoint Inspector is a product that allows the remote collection of data from phones, computers, and other devices. This is important because unlike EUID, which requires the targets device to be connected to the physical EUID, Endpoint Inspector can extract the data from the device even if it's on the other side of the world. The product is marketed to corporations to monitor their employees activities at the office or when they're working from home. But who knows whether government agencies are also using this remote extraction technology.
Celebrate Pathfinder is a product that takes all of the data that is downloaded using other Celebrite products and then uses AI to analyze it in a fraction of the time that it would take humans to do. For example, in a matter of minutes, it scour all of your photos, videos, texts, and social media to reveal your interactions with certain people, your movements, and your activities.
So, that's an overview of the main products that CBRE currently offers, but it's important to remember that the hacking capabilities of this company are constantly evolving. Celbrite invests very heavily in research and development which can be spearheaded by the ongoing recruitment of the best and brightest of elite Israeli intelligence units like 8200. In addition, the company acquires other cyber security companies so that it can take their IP and use it to expand Celebrite surveillance capacity. A very recent example of this is Celebrite's $200 million purchase of the US startup Corellium, which specializes in hacking phones via different means. Corellium is no stranger to controversy itself, having reportedly offered its product to companies with appalling human rights records, such as the Israeli corporation NSO Group, which is responsible for the infamous Pegasus spywear that was used by repressive regimes around the world against journalists and human rights activists. It's worth mentioning that like Celebrite, NSO Group recruits almost exclusively from Israeli intelligence units, including 8200 for its research team.
Okay, so now it's time to talk about the really problematic ways that celebrate technology is used in Australia. Before I get into the detail, I just want to explain a basic principle that the government at least usually pays lip service to when making laws that infringe upon our privacy. It's long been recognized that there is this tension between on the one hand the public interest in the police being able to have the tools they need to fight crime and on the other hand the interests of people in having their privacy and civil liberties protected. Lawmakers claim that they try to strike the right balance between these two competing interests. And the way that they normally do this is by strictly regulating the use of powers that undermine our privacy and by creating mechanisms for external oversight and review of these powers.
So let's take phone tapping as an example. Intercepting someone's phone calls without them knowing is obviously a highly invasive form of surveillance. And it's for this reason that it's highly regulated. For example, only a handful of agencies are allowed to do it. They generally need a warrant first and they can only get a warrant in fairly limited circumstances. On top of that, each year the Federal Attorney General publishes a report about telephone interception which sets out info about the extent of phone tapping in Australia and how effective it's been. This kind of accountability is vital because it's the only way to know if these powers are being abused and if they're actually getting results.
So, with that principle in mind, let's get back to Celebrite. It's difficult to think of anything more invasive than the downloading of your mobile phone. I mean, after all, your phone is usually where the most sensitive info about you and your private life is stored. Celebrate products can get all of that info and more. And so, you'd think that their use in Australia would be subject to the most stringent restrictions and oversight, right? Well, that's not the case at all. In fact, the way that celebrate products are used in this country raises some serious concerns for our privacy and civil liberties. And that's what I'm going to explore now.
For starters, Celbrite products are used by a wide range of government agencies and not just law enforcement. At the federal level, there have been 171 contracts between Celbrite and various government agencies since 2011. These agencies have included the AFP, the Department of Defense, the Department of Home Affairs, ASICH, the ATO, and more. One of the more controversial contracts is that with services Australia, which allows center link to use celebrate technology in investigations of people suspected of making false claims for social security. Another controversial contract is that with the sports integrity unit, formerly known as the Australian Sports Anti-Doping Authority, which has used Celbrite technology to investigate the use by athletes of performance-enhancing drugs.
Now, it's important to understand that these are just the federal agencies that have contracts with Celebrite and not all of the agencies who use Celebrite technology. For example, in 2023, Services Australia admitted that it had shared Celebrite's phone hacking technology with the Department of Education as well as other unnamed agencies. We don't know which other agencies are using Celebrite products, and that's part of the problem. The same problem exists at the state and territory level where even less is known about the use of celebrate technology. We know that CBR is contracts with at least some state police forces as well as other investigative bodies like the New South Wales Independent Commission against corruption. But we don't know whether any of these state agencies are sharing Celebrite technology with other state agencies and in what circumstances.
Something interesting I learned when I was doing research for this story is that the Australian government is not only a client of Celbrite but it also pushes Celebrite onto other countries. People familiar with the geopolitics of this region might know that the Australian government wields a lot of influence over some of our smaller neighbors. And one of the way that this manifests is with policing. The Australian federal police has a big say in how the police forces of our neighboring countries operate. And in the last few years, the Australian government has provided celebrate products to police forces in countries including Vanuatu, Papa Newu Guinea, and possibly the Solomon Islands. The AFP also provides Celbrite training to these and other Pacific nations.
Okay, so now that you know some of the agencies using Celbrite technology, let's talk about the way they're using it. For me, this is one of the most important aspects of the story. Yet, it's something that most people don't know about. Why is it so important? Because there are very few, if any, known restrictions on the use of Celebrite tools by these agencies. And this has resulted in mobile phones being hacked on a large scale in this country.
To illustrate the point, I'm going to focus on the New South Wales Police Force because that's the agency that I deal with most as a criminal lawyer based in Sydney. In New South Wales, none of the restrictions that apply to other police powers to protect people's privacy and civil liberties apply to the use of celebrate technology. For instance, the cops generally need a warrant if they want to do things like search your home, tap your phone, or install a listening device in your car to secretly record the conversations you have with people. To get these warrants, the cops need to go to an independent authority like a judge or a magistrate and present some evidence justifying the warrant being issued. What this evidence needs to prove depends on the warrant being requested. But it basically requires the cops to show they've got a good reason for the request. For example, if the cops are applying for a warrant to search your house, they need to demonstrate that they've got reasonable grounds to believe that they'll find the evidence they're looking for at your house. Now, look, I don't want to pretend that the system is perfect, and there are plenty of critics who argue that these warrants are given out too easily, but at least it's something. It provides some independent oversight, and it deters cops from making dodgy applications for warrants.
Now, when it comes to Celebrite, there is no legislation in New South Wales or for that matter in any Australian jurisdiction that requires the police to get a warrant to search your phone. And from experience, I can tell you that the cops take the view that if they get their hands on your phone, they can celebrate it without approval from anyone. So, how can they get your phone? Well, there are several ways. One is if you've been arrested for whatever reason. In that situation, the police can seize your phone without a warrant if they reasonably suspect that it will provide evidence of the commission of any offense, regardless of how trivial it is. But even if you're not under arrest, the police have the power to take your phone without a warrant in various situations. For example, the police have the power to stop and search you and your car without a warrant when they have reasonable grounds to suspect that you're in possession of a prohibited drug. Now, it's important to understand that there's no minimum quantity of the drug. So, if the cops suspect that you've got even just a tiny amount of weed or coke on you, they can search you. And once they search you, they can seize your phone if they reasonably suspect it might provide evidence of what they call a relevant offense, which covers most crimes.
An even easier way for the police to get your phone is if they do it with your consent. Now, you might be asking, why would anyone agree to give up their phone to the police? Well, it actually happens a lot. You see, most people don't know their rights, and they're intimidated by the police. They think that anything a police officer asks them to do, they have to do. And a lot of cops know this and take advantage of it.
Now, I should add that some defense lawyers in Australia have tried to challenge the status quo. And they've argued that the police actually do need a search warrant to celebrate your phone. In doing so, they've relied on a 2014 case from the United States called Riley versus California. In Riley, the US Supreme Court held that the police do generally need a search warrant to search a mobile phone. One of the main reasons for its decision was its finding that searching a phone is more akin to searching someone's house, which you need a warrant for, than searching their person, which you don't need a warrant for. In fact, the court found that searching someone's phone can be even more intrusive than searching their home. Now, if this argument made sense back in 2014, it makes a lot more sense in 2025, given how far the technology has evolved since then. Our phones now hold a lot more sensitive data than they did a decade ago. And with the help of Celebrite, the police now have the ability to download all of it. But unfortunately, these legal challenges in Australia have been unsuccessful. And the position remains that the police don't need a warrant to celebrate your phone. And it's important to add that in my experience, a lot of cops download phones as standard practice, regardless of how trivial the case is and whether they actually think it's going to help their investigation.
Now, in some cases, I've been able to persuade the police not to celebrate a client's phone. But it's usually up to the goodwill of the individual officer, and that's something we don't always see a lot of. The result of all of this is that the police are downloading mobile phones at an alarming rate in this state. Now, we don't actually know how many phones New South Wales police are celebrating each year because they're not required to report this, but we know from anecdotal evidence that it's massive. To give you an idea, just with my practice, each year I received dozens of celebrate reports of phones that have been downloaded, and I'm just one criminal lawyer of thousands in this state. The other day, I spoke with a colleague who had recently cross-examined an officer at a hearing. The officer gave evidence that she downloads about 20 mobile phones per week. And that's just one police officer in one police station. There are more than 400 police stations in New South Wales alone. So I don't think it's farfetched to estimate that the New South Wales Police Force is downloading tens of thousands of phones each year. And that's just one agency in one state. Just imagine what the number is nationwide.
Now, some of you might be thinking, "Okay, but the police are only doing this to criminals, right? So who cares?" Well, the first thing to remember is that not everyone who the police stop and search ends up being charged, and not everyone who is charged ends up being found guilty. A large number of my clients who've had their phones celebrated end up walking free.
Another important thing to know is that the police also regularly celebrate the phones of victims and witnesses of crimes. I see this especially in cases involving allegations of sexual assault, where the police will download the complainant's phone to get the messages they exchange with the accused or with their friends about the incident. Now, plenty of times the messages are relevant and definitely should be disclosed to the defense, but there are real issues with the way the police go about it sometimes. Firstly, by using celebrites you fed, the police don't just download the relevant messages from the complainant's phone, but all of the data. Secondly, the police will then often provide the defense with a copy of the entire download of the complainant's phone. Now again, that's helpful for us defense lawyers because it can contain relevant information, but the truth is the vast majority of the data is completely irrelevant and often very private.
An example of this happening was in the high-profile sexual assault prosecution of Bruce Leman a few years ago. In that case, the Australian Federal Police provided the entire celebrate download of Britney Higgins phone, which even included her counseling notes to Leman's lawyers. Some of the phone's content, like text messages she had sent to certain people prior to making the complaint, were clearly relevant and damaging to her credibility, but most of the data was entirely relevant or otherwise inadmissible, like her counseling notes, and shouldn't have been served. Now, the police in that case said they gave the defense Miss Higgins phone download by mistake, but I've seen several cases where it's been done knowingly. In other cases, the police might not serve the entire download of the phone, but they'll still serve a lot more than they should. For example, a year ago, I was representing a guy who'd been charged with sexually assaulting a woman during a hinge date. When the police served the prosecution evidence on my office, it included a partial celebrate download of her phone that contained sexually explicit messages that she had exchanged with another guy that had nothing to do with the case. The messages were never going to be admitted as evidence at my client's trial, but the cops gave them to us anyway.
Another major issue is the lack of communication by police when they ask alleged victims to hand over their phones. To give you an example, a few months ago, I gave advice to a woman who is an alleged victim of sexual assault and domestic violence by her exartner. When she first made the complaint, she showed the police the relevant messages on her phone. After her ex was charged, the cops asked for the phone so they could download the messages. But at no stage did they tell her that they were going to download her entire phone and then give it to her ex's lawyers. So, she was understandably pretty distressed when she found out that her ex now had a copy of all of her messages with her friends and family, her photos, her health data, everything. She told me that had she known the police were going to do this, she might have thought twice about handing over her phone to them. It might surprise you to know that what I've just described is actually a pretty common experience for sexual assault complainers. In fact, it's so common that in the recent inquiry by the Australian law reform commission into justice responses to sexual violence, the advocacy group Full Stop Australia recommended a review of this celebrating practice to protect victims privacy. Interestingly, the law reform commission didn't adopt the recommendation in its final report. But regardless, I think this is a phenomenon that will receive a lot more media attention in the years to come.
The next issue I want to talk about briefly is the lack of oversight when it comes to celebrate use. There are laws in this country that are designed to provide some accountability to the public about the use of police powers that undermine our civil liberties. For example, like I mentioned a bit earlier, each year the federal attorney general publishes a report that discloses important info about the use of telephone interception by law enforcement agencies in this country. This info includes how many agencies applied for phone tapping warrants, which crimes these agencies were investigating, how many warrants were granted, and how many were refused. So, we can see from last year's annual report that 3007 interception warrants were granted, of which more than a third were for serious drug offenses, followed by violence offenses and murder. The report also provides info about the effectiveness of telephone interception, such as how many people were arrested on the basis of evidence obtained by phone tapping, the types of offenses that these people were arrested for, and how many of them went on to be convicted. So, the same annual report from last year discloses that information obtained under phone typing warrants led to 1,592 arrests and 1,60 convictions. The Commonwealth Attorney General has a similar reporting obligation for other police powers, such as stored communications warrants, which are what the police use to access text messages stored by providers like Telra and Vodafone, and surveillance device warrants, which are what the police need to install listening devices, hidden cameras, and tracking devices. Here in New South Wales, similar reports are prepared each year about the use of various police powers, including surveillance devices and code search warrants.
Now, in my view, the use of CBRE technology to download your phone is far more invasive than all of the police powers that I've just mentioned. Yet, none of the mechanisms designed to provide accountability for their use apply to Celebrite. As a result, we have no idea how many phones each agency is celebrating per year, what their reasons are for doing it, or how effective it's been.
Okay, so the last topic I want to cover today is what happens with all of this highly sensitive data once it's downloaded from your phone. Now, I should make clear that everything I'm about to tell you is based on my own professional experience and research and not any law policy. And the simple reason for that is that there are no laws governing celebrate use in this country. And no government agency has published policies about celebrate use either. In fact, from conversations I've had with federal and state police officers, it seems that no policies or guidelines even exist. And this raises some real concerns. For example, I'm not aware of any requirement for the cops to destroy the data they've downloaded from a phone after any period of time. And this is not just for phones of people who end up being found guilty of a crime, but all phones that are downloaded. So, let's say the cops celebrate your phone because they suspect you've done a crime, but after they go through the downloaded data, they realize they got it wrong and no charges are laid. Well, they don't have to delete the download of your phone and it'll be stored on their database indefinitely. The same goes if you're an alleged victim of crime. To use Britney Higgins as an example, again, the celebrate download of her phone sat with the police long after the criminal prosecution of Lehman being discontinued. And all 56,000 pages of it ended up being subpoenaed in entirely separate defamation proceedings brought by Lehman against Network 10 and then in defamation proceedings brought by former Senator Linda Reynolds against Miss Higgins.
Another issue is that there are practically no constraints on how the data that's downloaded from our phones can be used. So, let's say the cops are investigating a robbery and you're a witness who recorded some videos of the crime and then sent them to your mates. The cops then ask if they can download the videos and messages and you, not knowing your rights, agree and give them your phone. The police then celebrate your phone and see some messages showing that you shared some pills with some mates at a music festival 8 years ago. Well, in theory, there's nothing stopping the cops from using that evidence to charge you with drug supply, even though it has nothing to do with what they were investigating in the first place, and you weren't even a suspect. There also doesn't appear to be anything from stopping the cops from sharing the data that's downloaded from our phones with other agencies, and with those agencies then sharing the data with other agencies. So, if your phone is celebrated, it's almost impossible to know where your data will end up and who will get to see it.
Perhaps the most important question with all of this is can celebrate itself access the data that is downloaded from people's phones. In an interview with Israeli media in 2019, then CEO Yossi Karal boasted that Celebrite controlled all products remotely. Now, that could be seen as an admission about access to data, but I accept it's not entirely clear what he meant. As a lawyer, I'm evidence-based and I try to avoid unfounded speculation. Having said that, and just based on what we've spoken about until now, I don't think it's some far-fetched conspiracy theory to think that Celbrite may be able to access the data that's being extracted from people's phones using its products. I mean, let's not forget that we're talking about a company that is made up of elite Israeli army intelligence veterans, and it still has very close ties with the Israeli military. So, if any company has the knowhow and the motive to collect the data, it's Celbrite. But let's look at the evidence. Specifically, I'm going to talk about two documents that are highly revealing, but as far as I'm aware, have never been reported on. The documents are contracts between Celbrite and Services Australia. One is a license agreement for the use of Celbrite products, and the other is a contract for services provided by Celebrite. I can confirm that they're both authentic because I obtained them myself directly from Services Australia last month. Both of the contracts contain some really disconcerting clauses that I was genuinely shocked to see. like the clause that requires Services Australia to provide Celbrite with its internal IT policy or the clause designed to stop Service Australia's employees from telling Australian police about what Celbrite can do. But for today's purposes, I'm just going to focus on the clauses relevant to this question of access to data.
Under the license agreement, Services Australia authorizes Celbride to in certain circumstances access all devices, data and media contained on them, obtain and retain personal data on the devices, and access and intercept communications on the devices. The services agreement goes even further, authorizing Celbrite to access or modify any data on any device it is providing services for, as well as collecting, recording, disclosing, and transferring personal information on the device. The services are defined in the contract to include unlocking and extraction of devices and then searching and processing the data contained in them. So these contracts provide clear evidence that at least in some situations celebrate can access the data that's being downloaded from our phones. How often this is occurring, we don't know and we can't find out due to the complete lack of transparency.
Now the contracts I've just spoken about are only with Services Australia. So, you might be asking, are there similar clauses in Celbrite's contracts with other agencies? Well, from the research I've carried out, the answer seems to be yes. Although it's not easy to find, Celebrite's current license agreement is available on its website. The agreement is almost identical to the one with Services Australia, and crucially, it includes the same clause authorizing Celebrite to access data held by customers. The only other celebrate license agreement I've been able to locate online is that from the Gilbert Police Department in Arizona, USA. It was buried at the back of some council minutes, and so I'm not sure if many people have even seen it before. Here you can see the same clause authorizing Celebrite's access to customer data in certain circumstances. So that's CBR's license agreement, but what about it contract for services? Well, there doesn't appear to be any copies of it publicly available, but I'd be surprised if the one I've obtained from Services Australia is not standard. From the way the contract is drafted, it appears to be generic. And also, most tech companies generally use the same contract with all customers to ensure consistency.
Another troubling piece of this puzzle is that we don't know where government agencies store the data they download from our phones. Now, I know from experience that police in this country have traditionally saved their data on computers and hard drives at the station. However, Celbrite is slowly but surely transitioning its products to the cloud, and some products now operate exclusively on the cloud. Here is a promo video from last September for Celbrite's Pathfinder product, encouraging customers to use the product and host its data on the cloud instead of on local servers. >> Deploying in the cloud allows your agency to invest more time, money, and resources into fulfilling your core mission.
Now, it's important to bear in mind that Pathfinder analyzes the data downloaded using all Celbrite products. So presumably by using Pathfinder on the cloud, the agencies are uploading all of the data they've extracted from our phones and devices onto the cloud. Now this begs the question, why is CBR trying to get government agencies to store all of this data on the cloud? Can Celebrate access it more easily if it's on the cloud? Well, you won't find much information about this in the public domain, but I was able to locate this recent promo video from Celbrite where the spokesperson described what happens once data is remotely extracted from a phone or other device using endpoint inspector. >> Uh once that collection completes, um that's the UFD file and that's that full kind of forensic image. Um, and that's going to go to Celebrate where we're going to actually parse out that data. So, it is going to come to Celebrate, parse it into the UFDR, convert it the messaging to the RSMF. Um, and then we're going to transfer it over to Relativity 1 um in the workspace that was set up during the job collection.
Now, she goes on in the video to claim that Celbrite deletes all the data once it's been processed for the customer. But how do we know if this is true? It's worth mentioning that the cloud that CBRE uses is the Amazon Web Services or AWS cloud. This raises concerns of its own because like Celbrite, AWS has close ties to the Israeli military. Specifically, AWS provides computing services, AI, and other services to the Israeli military under a 1.2 billion contract known as Project Nimbus.
Now, I want to make clear that I'm not positively alleging that Celebrite can access all of the data that's being downloaded from our phones using its products. There's simply not enough evidence for me to make that claim. But I am saying that there's a real risk that they might be doing this. And in my opinion, that's not a risk worth taking. Okay. So,
Now that I've just set out a very long list of concerns about Celbrite and its use in Australia, I want to end with two main recommendations. The first is that the federal and state governments reconsider their relationship with Celite altogether.
Now, there's no shortage of reasons why they should drop Celebrite. From a moral standpoint, it's a no-brainer. Celebrite has close ties with the Israeli army, which uses its surveillance products to further its brutal and illegal occupation of the West Bank. And although the details aren't clear, we also know that Celebrite has assisted the Israeli military while they carry out what is now widely considered to be a genocide in Gaza. On top of that, Celebrite has a track record of selling its products to repressive regimes, which have used them against journalists, dissident, and activists.
Now, maybe you don't care so much about arguments based on morals or human rights, and you only care about what's in Australia's best interest. Well, there's still a really compelling reason to ditch CBRE, and that's security. As I've explained in this video, there are really good reasons not to trust Celebrate with our data. At the end of the day, it's a foreign intelligence company made up of former spies from an intelligence unit of a foreign state to which it still appears to have close ties. And I should add that Israel is not just any foreign state, but one with a long history of spying on its allies. Indeed, Israel has even been credibly accused of having previously spied in Australia. Celebrate has the means and the motive to access our data, and it seems that it may already be doing this in some cases. It goes without saying that the protection of the personal data of Australian citizens should be a priority of our elected government and the law enforcement agencies in this country. And it's not like our government doesn't have any other options. Although I haven't covered them in this video, there are other companies that offer similar products to Celbrite like Magnet Forensics, MSAB, and Exterero. In fact, the Department of Home Affairs, which is what the Australian Border Force is a part of, recently switched from Celebrite to Magnet Forensics. Now, I'm not saying these competitors are perfect. Far from it. But they don't give rise to the same level of human rights and security concerns that Celbrite does.
My second recommendation is that the federal and state government should enact legislation regulating the use of phone extraction products whether or not it's with Celbrite. The legislation will need to differ depending on the agency, but the key principles will be the same. For the police, some of the main provisions should include the following. One, there should be a ban on the police downloading our phones unless they've got a warrant. If there's a legitimate forensic need for the cops to get access to a phone, then they can explain that to a judge in the same way they would have to if they wanted to search your home or tap your phone. Two, the police should only be able to apply for warrants when they're investigating serious criminal offenses and not minor ones. Three, the police should only be permitted to download and review data that is likely to be relevant to their investigation and not the entire phone's content. Four, the police should only be able to store the data for as long as is necessary for the investigation or prosecution. And if no charges are laid or the defendant is found not guilty, the data should be deleted. And lastly, five, each year the police should be required to disclose the extent and effectiveness of the use of these products and there should be independent auditing. Ultimately, this is one of the only ways to ensure that this highly intrusive technology is not being abused.
Okay, so that brings me to the end of the first episode of the what and the why. If you like this video, please give it a thumbs up and leave a comment to help boost it in the algorithm. Each episode will be about a completely different topic, but they'll all be about matters that hopefully you'll find interesting and important. So, if you'd like to see more, please subscribe to the channel and let your friends know about it. Until next time.