Live data from Hacker News

0-click deanonymization attack targeting Signal, Discord, other platforms

gist.github.com

171–180 of 474 posts

Re: 0-click deanonymization attack targeting Signal, Discord, other platforms

#171
post #146

Cool! Contrary to some of the other posters I think this definitely counts as deanonymization, or at least is close enough. How anonymous would satoshi be today if we had his location to within 250 miles? Repeated applications of this attack (maybe disguised somehow?) could let you track someone’s travel over time, and it is usually only takes 4-5 zip code sized locations to uniquely identify someone.

The counter point is that anyone who cares about being anonymous is using methods to disguise their identity that cannot be compromised by this attack, e.g: a VPN. Plus, there are much more effective versions of this attack, like sending a link to an endpoint that you control -- getting someone to click a link isn't hard if you're considered trustworthy enough to send them notifications. And less technical versions, like correlating when the user is online vs. offline with timezones around the world.

The method that both Apple and Cloudflare use in their own privacy software (iCloud Private Relay for apple, WARP for Cloudflare) is specifically based on the idea that your region is not information that reveals your identity. If you enable Apple Private Relay, your origin IP will be obscured but the IP your traffic is routed through will be in the same country -- same principle.

https://www.apple.com/icloud/docs/iCloud_Private_Relay_Overv...

This attack is academically interesting and novel but it's not "deanonymization".

Re: 0-click deanonymization attack targeting Signal, Discord, other platforms

#172
post #31

What's old is new. Does anyone remember the forum signatures that would display the viewers IP address and location on a little wooden signpost held up by a troll-looking creature? https://cdn.geekzone.co.nz/images/forums/danasoftcache.jpg

I was fascinated by this once I learned how it worked. At the time I was learning php and wrote a script that would draw graphics based on the requesting ip address and return as gif, then used that as my avatar on a few phpbbs. Learned a lot.

Re: 0-click deanonymization attack targeting Signal, Discord, other platforms

#173
post #32

> it's possible for an attacker to run a cache geolocation attack to find out which local datacenter they're near--similar to how law enforcement track mobile devices through cell phone towers. very much disagree on this, they track mobile devices through your connection strength to multiple cellular towers while this attack proves which singular datacenter the victim is nearest. Don’t get me wrong the write up is re…

[deleted]

Re: 0-click deanonymization attack targeting Signal, Discord, other platforms

#175
post #81

Earlier quoted context omitted.

It's not really narrowing it down to 250 miles; its narrowing it down to a circle whose radius is at least 250 miles or ~196,000mi^2. My closest Cloudflare CDN is just listed as "DFW". The DFW metro area is about 8,700mi^2, and I imagine I could be even further than the "metro area" and still get the "DFW" Cloudflare datacenter. In their little video animation, the area inside the overlap of those two circles encompa…

I think it's still useful. Going from "we don't know where Osama bin Laden is at all" to "he's somewhere in Pakistan".

This assumes that Osama bin Laden has poor enough opsec that he's using (eg.) Discord without a proxy. State actors have much more sophisticated techniques available.

(It's still an interesting vector, though! But it's true that the headline and writeup are a bit sensationalized.)

Re: 0-click deanonymization attack targeting Signal, Discord, other platforms

#176
post #128

Earlier quoted context omitted.

>The real-world application (and potential danger) is when this data is combined with other data. De-anonymization techniques using sparse datasets has been an active area of research for at least 15 years and it is often surprising to people how much can be gleaned from a few pieces of seemingly unconnected data. Seems pretty handwavy. Can you describe concretely how this would work?

> Seems pretty handwavy. It has a whole Wikipedia article and everything. https://en.wikipedia.org/wiki/De-anonymization#Re-identifica... > Can you describe concretely how this would work? Here's one of the earlier papers I remember off-hand, demonstrating one methodology. New (and improvements to existing) statistical techniques have happened in the ~18 years since this was published. Not to mention their is signifi…

>"We apply our de-anonymization methodology to the Netflix Prize dataset, which contains anonymous movie ratings of 500,000 subscribers of Netflix, the world’s largest online movie rental service. We demonstrate that an adversary who knows only a little bit about an individual subscriber can easily identify this subscriber’s record in the dataset."

> [...]

"Researchers at MIT and the Université catholique de Louvain, in Belgium, analyzed data on 1.5 million cellphone users in a small European country over a span of 15 months and found that just four points of reference, with fairly low spatial and temporal resolution, was enough to uniquely identify 95 percent of them." [...] "A few Twitter posts would probably provide all the information you needed, if they contained specific information about the person's whereabouts."

The only reason the two attacks work is that you have access to a bunch of uncorrelated data points. That is, ratings for various shows and their dates, and cellphone movement patterns. It's unclear how you could extend this to some guy you're trying to dox on signal. The geo info is relatively coarse and stays static, so trying to single out a single person is going to be difficult. To put another way, "guy was vaguely near New York on these dates" doesn't narrow down the search parameters by much. That's going to be true for millions of people.

Re: 0-click deanonymization attack targeting Signal, Discord, other platforms

#177
post #12

"Signal instantly dismissed my report" "Telegram, another privacy-focused application, is completely invulnerable to this attack" "Discord […] citing this as a Cloudflare issue other consumers are also vulnerable to" "Cloudflare ended up completing patching the bug" I wish Signal would react differently. I still remember the bubble color controversy when they changed their mind after the backlash and not before. :-)

Is there really any difference between dismissing the report or "citing this as a Cloudflare issue"?

Not in practice.

> There's clearly a problem here as Cloudflare says consumers are responsible for protecting themselves against these types of attacks, while consumers (ex. Discord) are putting the blame on Cloudflare.

Re: 0-click deanonymization attack targeting Signal, Discord, other platforms

#178
post #176

Earlier quoted context omitted.

> Seems pretty handwavy. It has a whole Wikipedia article and everything. https://en.wikipedia.org/wiki/De-anonymization#Re-identifica... > Can you describe concretely how this would work? Here's one of the earlier papers I remember off-hand, demonstrating one methodology. New (and improvements to existing) statistical techniques have happened in the ~18 years since this was published. Not to mention their is signifi…

>"We apply our de-anonymization methodology to the Netflix Prize dataset, which contains anonymous movie ratings of 500,000 subscribers of Netflix, the world’s largest online movie rental service. We demonstrate that an adversary who knows only a little bit about an individual subscriber can easily identify this subscriber’s record in the dataset." > [...] "Researchers at MIT and the Université catholique de Louvain,…

>To put another way, "guy was vaguely near New York on these dates" doesn't narrow down the search parameters by much.

That's why I said that this data alone is probably worthless, but can gain value when combined with other data.("As a piece of data alone, the results are probably not of significant use")

The combining of data is the important bit and the entire emphasis of both of my other comments.

Two pieces of otherwise anonymous data can, when combined, lead to re-identification.

Re: 0-click deanonymization attack targeting Signal, Discord, other platforms

#179
post #166

Earlier quoted context omitted.

Seems contrived. What type of a person cares about deanonymization attacks and nation-states trying to find him, but doesn't have an always-on VPN? Even without this attack, not using a VPN means you're 1 wrong click/tap away (if you accidentally clicked on a link) from leaking your IP.

Right, agreed that VPN is the primary mitigation against this from a user perspective. But opsec is hard, especially when the attack can be triggered by a notification when the victim might not be expecting it and might not have VPN enabled (e.g. maybe they only enable VPN when using Discord). (But notifications are already a bad idea for opsec anyway.)

>But opsec is hard [...]

That's why the attack is contrived. If you have poor opsec you don't need need this attack at all. You can probably get the victim's exact IP by getting him to click on a link, or sending him an email. If he has good opsec he's going to be using a VPN that renders this attack useless. For this attack to be valuable you need a guy who has such good opsec that you can't get his location any other way, but for whatever reason isn't using an always-online VPN.

Re: 0-click deanonymization attack targeting Signal, Discord, other platforms

#180
Looking at the locations where Cloudflare has their servers [1] in the middle of Europe. With Geneva, Zurich and Munich there is definitely the possibility that this attack on Signal will leak whether someone is at home or not.

I don't understand how Signal could dismiss this so easily. I'm starting get a bad feeling about their responses to these "low" stakes attacks. They already missed the ball on the database encryption mishap on desktop.

[1]: https://www.cloudflare.com/network/

Post reply on HN