Live data from Hacker News

0-click deanonymization attack targeting Signal, Discord, other platforms

gist.github.com

181–190 of 474 posts

Re: 0-click deanonymization attack targeting Signal, Discord, other platforms

#181
post #140

What is the benefit of caching images in a cdn for Signal? Assuming local client-side caching, the total number of requests for that resource should be very small, probably one in the vast majority of cases. On an unrelated note, it seems like CloudFront could very easily fix this by not returning the cf-ray header, or at least having an option for the customer to remove it. Although, it might still be possible to ge…

So that law enforcement can ask Cloudflare for the IP logs... Signal is a joke.

https://simplex.chat/

Re: 0-click deanonymization attack targeting Signal, Discord, other platforms

#182
post #156

Earlier quoted context omitted.

Hello, I'm an organizer for a system to coordinate multiple mutual aid networks, many of which are only organizing by Signal & Protonmail exclusively because they think they're secure and private. People who are doing work to help people in ways the state tries to prevent (like giving people food) rely on this tech. These are the same groups who were able to mobilize so quickly to respond to the LA fires, but the Red…

What groups did the police and Red Cross shut down? Any links?

[deleted]

Re: 0-click deanonymization attack targeting Signal, Discord, other platforms

#184
post #158

Earlier quoted context omitted.

You can disable the auto-download. Settings > Data and storage > Media auto-download, you can choose what to auto download for mobile data/wifi/roaming.

it looks like it can’t be disabled for view-once media (or at least, that’s what the settings screen says)

I wonder if view-once media is even handled the same way as a regular attachment (using CF) or is sent more like a regular message.

I imagine if one really wanted it to be view-once, it wouldn't go to a CDN.

Thanks for pointing this out!

Re: 0-click deanonymization attack targeting Signal, Discord, other platforms

#185

There was mention that the Teleport tool no longer works after the bugfix of the underlying issue (calling other cf locations via Workers and an internal subnet). It seemed like the ability to query which caches HIT on the dye-test image relied on being able to call out to each other DC. Without this control over the route (driving the probing of which caches were hit), the attack would no longer work, right?

There is another method to query the caches. This is mentioned in the article.

Re: 0-click deanonymization attack targeting Signal, Discord, other platforms

#186

why is the picture not simply cached near the sender as opposed to the receiver? is there any good reason for deciding this way on the part of Signal et al?

The attacker can't be forced to make a request. In this PoC the attacker disabled their own outgoing image requests.

But that wouldn't help anyway, even if the image could be cached near the sender first, or the signal server prewarmed some other cache. After the victim opened the image, the attacker would see two locations that have the image cached, and could easily deduce which one is the victim's location (e.g. if Signal pre-warmed a random cache, repeating the attack a couple of times would be enough to eliminate the randomness).

Re: 0-click deanonymization attack targeting Signal, Discord, other platforms

#187

Earlier quoted context omitted.

> Given Cloudflare's less-than-straight approach to sales, it is astonishing the words "secure" and "Signal" ever appear in the same sentence. This is an overly binary take. Security is all about threat models, and for most of us the threat model that Signal is solving is "mainstream for-profit apps snoop on the contents of my messages and use them to build an advertising profile". Most of us using it are not using S…

Hello, I'm an organizer for a system to coordinate multiple mutual aid networks, many of which are only organizing by Signal & Protonmail exclusively because they think they're secure and private. People who are doing work to help people in ways the state tries to prevent (like giving people food) rely on this tech. These are the same groups who were able to mobilize so quickly to respond to the LA fires, but the Red…

This is why I say that it's overly binary, not incorrect. Some people do have such needs, and Signal can and should fix this for those people.

Re: 0-click deanonymization attack targeting Signal, Discord, other platforms

#188
post #135

Earlier quoted context omitted.

Did you even read it? There's no IP leak. And if you're a high target, then using some kind of proxy is literally the first step you take. The attack is nothing but an exaggeration and has no merit in real world

Yes, I read it. Information about your IP address is leaked, as that's how Cloudflare routes you to a given datacenter. And I strongly disagree that being able to uncover somebody's rough geographic location is not a privacy problem. I wouldn't be surprised if this, for example, lets you deduce if somebody is currently home, at work, or commuting (as all three ISPs might be hitting different Cloudflare datacenters).…

If you aren't comfortable broadcasting it, then maybe take measures so that it doesn't get to that point. Privacy is not by default, ever

Re: 0-click deanonymization attack targeting Signal, Discord, other platforms

#189
post #7

This is pretty interesting, and well documented. Great work! I wonder if there is a way to turn off notifications or if the approach is to simply not run such apps.

Not sure about mobile apps, but in Discord desktop there is an option under "settings -> notifications". Your browser may also have notification settings that would help.

This changes the attack from a 0-click attack to a 1-click attack.

Re: 0-click deanonymization attack targeting Signal, Discord, other platforms

#190
post #121

Earlier quoted context omitted.

It only takes 33 bits to identify someone. This reveals a couple of bits.

Not really. It's only true if the bits are uncorrelated, and you can acquire additional bits of information. I don't see how you can go from "this guy on the internet lives near Albuquerque, New Mexico" to "this guy is Walter Hartwell White, and lives at 308 Negra Arroyo Lane, Albuquerque, New Mexico, 87104" without massive opsec failures.

Every little bit helps.

You can plot the timestamps of every message, read receipt and emoji reaction, which gives you the timezone and hints at work schedule, commute duration and vacations.

Often people will post photos or have profile pictures.

Say you have a photo taken at a random mcdonalds. That'd be 36'000 locations. Imagine cloudflare location and timezone help you narrow it down to new mexico. That's 80 locations. Small enough that you can look at every single one using street view and check where the photo actually was taken.

Now you can subpoena the McDonald's cctv footage and figure out who sent that picture.

Post reply on HN