What is the benefit of caching images in a cdn for Signal? Assuming local client-side caching, the total number of requests for that resource should be very small, probably one in the vast majority of cases. On an unrelated note, it seems like CloudFront could very easily fix this by not returning the cf-ray header, or at least having an option for the customer to remove it. Although, it might still be possible to ge…
0-click deanonymization attack targeting Signal, Discord, other platforms
181–190 of 474 posts
Re: 0-click deanonymization attack targeting Signal, Discord, other platforms
#182Earlier quoted context omitted.
Hello, I'm an organizer for a system to coordinate multiple mutual aid networks, many of which are only organizing by Signal & Protonmail exclusively because they think they're secure and private. People who are doing work to help people in ways the state tries to prevent (like giving people food) rely on this tech. These are the same groups who were able to mobilize so quickly to respond to the LA fires, but the Red…
What groups did the police and Red Cross shut down? Any links?
Re: 0-click deanonymization attack targeting Signal, Discord, other platforms
#183Re: 0-click deanonymization attack targeting Signal, Discord, other platforms
#184Earlier quoted context omitted.
You can disable the auto-download. Settings > Data and storage > Media auto-download, you can choose what to auto download for mobile data/wifi/roaming.
it looks like it can’t be disabled for view-once media (or at least, that’s what the settings screen says)
I imagine if one really wanted it to be view-once, it wouldn't go to a CDN.
Thanks for pointing this out!
Re: 0-click deanonymization attack targeting Signal, Discord, other platforms
#185There was mention that the Teleport tool no longer works after the bugfix of the underlying issue (calling other cf locations via Workers and an internal subnet). It seemed like the ability to query which caches HIT on the dye-test image relied on being able to call out to each other DC. Without this control over the route (driving the probing of which caches were hit), the attack would no longer work, right?
Re: 0-click deanonymization attack targeting Signal, Discord, other platforms
#186why is the picture not simply cached near the sender as opposed to the receiver? is there any good reason for deciding this way on the part of Signal et al?
But that wouldn't help anyway, even if the image could be cached near the sender first, or the signal server prewarmed some other cache. After the victim opened the image, the attacker would see two locations that have the image cached, and could easily deduce which one is the victim's location (e.g. if Signal pre-warmed a random cache, repeating the attack a couple of times would be enough to eliminate the randomness).
Re: 0-click deanonymization attack targeting Signal, Discord, other platforms
#187Earlier quoted context omitted.
> Given Cloudflare's less-than-straight approach to sales, it is astonishing the words "secure" and "Signal" ever appear in the same sentence. This is an overly binary take. Security is all about threat models, and for most of us the threat model that Signal is solving is "mainstream for-profit apps snoop on the contents of my messages and use them to build an advertising profile". Most of us using it are not using S…
Hello, I'm an organizer for a system to coordinate multiple mutual aid networks, many of which are only organizing by Signal & Protonmail exclusively because they think they're secure and private. People who are doing work to help people in ways the state tries to prevent (like giving people food) rely on this tech. These are the same groups who were able to mobilize so quickly to respond to the LA fires, but the Red…
Re: 0-click deanonymization attack targeting Signal, Discord, other platforms
#188Earlier quoted context omitted.
Did you even read it? There's no IP leak. And if you're a high target, then using some kind of proxy is literally the first step you take. The attack is nothing but an exaggeration and has no merit in real world
Yes, I read it. Information about your IP address is leaked, as that's how Cloudflare routes you to a given datacenter. And I strongly disagree that being able to uncover somebody's rough geographic location is not a privacy problem. I wouldn't be surprised if this, for example, lets you deduce if somebody is currently home, at work, or commuting (as all three ISPs might be hitting different Cloudflare datacenters).…
Re: 0-click deanonymization attack targeting Signal, Discord, other platforms
#189This is pretty interesting, and well documented. Great work! I wonder if there is a way to turn off notifications or if the approach is to simply not run such apps.
This changes the attack from a 0-click attack to a 1-click attack.
Re: 0-click deanonymization attack targeting Signal, Discord, other platforms
#190Earlier quoted context omitted.
It only takes 33 bits to identify someone. This reveals a couple of bits.
Not really. It's only true if the bits are uncorrelated, and you can acquire additional bits of information. I don't see how you can go from "this guy on the internet lives near Albuquerque, New Mexico" to "this guy is Walter Hartwell White, and lives at 308 Negra Arroyo Lane, Albuquerque, New Mexico, 87104" without massive opsec failures.
You can plot the timestamps of every message, read receipt and emoji reaction, which gives you the timezone and hints at work schedule, commute duration and vacations.
Often people will post photos or have profile pictures.
Say you have a photo taken at a random mcdonalds. That'd be 36'000 locations. Imagine cloudflare location and timezone help you narrow it down to new mexico. That's 80 locations. Small enough that you can look at every single one using street view and check where the photo actually was taken.
Now you can subpoena the McDonald's cctv footage and figure out who sent that picture.