Live data from Hacker News

0-click deanonymization attack targeting Signal, Discord, other platforms

gist.github.com

251–260 of 474 posts

Re: 0-click deanonymization attack targeting Signal, Discord, other platforms

#251

So if you send a picture to a Signal user, it's retrieved via cloudflare, and cached in a data center near that user; now you can look up the cache status and find the data center used. I'd say "deanonymization" is stretching it, unless the user is in the middle of nowhere (no other users near the data center). But interesting writeup anyway.

Combined with other information, it may identify someone reliably, just like you can with zip code, age and gender. For example, if you know this person is part of a group with members in several locations, or if you can corroborate someone's movements, etc.

For example, imagine someone suspected of sharing sensitive information with a journalist. They might have a short list of suspects, and use this technique to confirm which one it is. They might identify which journalist it is - maybe only a limited number cover this beat.

Re: 0-click deanonymization attack targeting Signal, Discord, other platforms

#252

Earlier quoted context omitted.

"Near a user" is also a big assumption. I'm ~200 miles to ORD and ~500 to IAD, but my ISP's peering & upstream arrangements mean Cloudflare serves my traffic 700 miles from DFW. But, at the same time: Cloudflare isn't going to serve me a cache from Seattle, Manchester, or Tokyo. Pinning down an unknown Signal user to even a rough geographic location is an important bit of metadata that could combine to unmask an indi…

I doubt how useful it would be as an attack. As a single point of info it tells you next to nothing. As part of a composition of other indicators it would be the weak link in the chain probably just causing noise for the not un-likly scenario where the person you're targeting is using a VPN. If it was any less specific we'd be talking about a deanonymization attack that outs whether or not a target is still on Earth.

> not un-likly scenario where the person you're targeting is using a VPN

Do you think a large proportion of Signal users also use VPNs? I'd expect it would be a higher proportion than the general population but still only a small minority.

Re: 0-click deanonymization attack targeting Signal, Discord, other platforms

#253

Wouldn't other user that sees the other person's profile picture also drum up the cache? This wouldn't work for someone in a large server.

The attacker uses a patched version of Signal to be able to intercept requests and to block a get request to the attachment they have just created. At least it is my understanding.

That’s just to be able to use their APIs to get the location of the sender.

Example you used the normal Signal app without patch and sending me a message, and I have the patched version.

Just to remove certificate pinning, to be able to see the API traffic because of encryption.

Re: 0-click deanonymization attack targeting Signal, Discord, other platforms

#254

Earlier quoted context omitted.

"Near a user" is also a big assumption. I'm ~200 miles to ORD and ~500 to IAD, but my ISP's peering & upstream arrangements mean Cloudflare serves my traffic 700 miles from DFW. But, at the same time: Cloudflare isn't going to serve me a cache from Seattle, Manchester, or Tokyo. Pinning down an unknown Signal user to even a rough geographic location is an important bit of metadata that could combine to unmask an indi…

for "normal people", that's a pain, but with enough resources,... Although. it has edge usecases even for "normal people": Eg. you suspect your coworker to be catfishing you on eg. discord, you know that he's in your city now, verify, then wait for him to leave for a vacation to somewhere abroad, check again.

It's not an edge case. Using multiple sources of information to paint a more complete picture is the norm. That's how marketing profiles work, for example.

Re: 0-click deanonymization attack targeting Signal, Discord, other platforms

#255
post #8

Earlier quoted context omitted.

It gets more interesting when you think about the impact on groups. Sending an image to a group is enough for all devices associated with that group to be identifiable from CloudFlare's side, who additionally see a giant chunk of unencrypted traffic from the same client addresses going to other web sites. Given Cloudflare's less-than-straight approach to sales, it is astonishing the words "secure" and "Signal" ever a…

> Given Cloudflare's less-than-straight approach to sales, it is astonishing the words "secure" and "Signal" ever appear in the same sentence. This is an overly binary take. Security is all about threat models, and for most of us the threat model that Signal is solving is "mainstream for-profit apps snoop on the contents of my messages and use them to build an advertising profile". Most of us using it are not using S…

I think the threat model of enough signal users to matter is nation-state actors, and signal should be secure against those actors by default so that they may hide among the entire signal user population

Re: 0-click deanonymization attack targeting Signal, Discord, other platforms

#256

Earlier quoted context omitted.

> Given Cloudflare's less-than-straight approach to sales, it is astonishing the words "secure" and "Signal" ever appear in the same sentence. This is an overly binary take. Security is all about threat models, and for most of us the threat model that Signal is solving is "mainstream for-profit apps snoop on the contents of my messages and use them to build an advertising profile". Most of us using it are not using S…

Hello, I'm an organizer for a system to coordinate multiple mutual aid networks, many of which are only organizing by Signal & Protonmail exclusively because they think they're secure and private. People who are doing work to help people in ways the state tries to prevent (like giving people food) rely on this tech. These are the same groups who were able to mobilize so quickly to respond to the LA fires, but the Red…

Someone should tell anyone who seeks confidentiality that no email is secure. Use Signal and enable the data retention (i.e., automatic message deletion) feature. By itself that is not perfectly secure, but it's a start.

Re: 0-click deanonymization attack targeting Signal, Discord, other platforms

#257
post #219

Earlier quoted context omitted.

> To put another way, "guy was vaguely near New York on these dates" doesn't narrow down the search parameters by much. That's why I said that this data alone is probably worthless, but can gain value when combined with other data.( "As a piece of data alone, the results are probably not of significant use" ) The combining of data is the important bit and the entire emphasis of both of my other comments. Two pieces o…

>Two pieces of otherwise anonymous data can, when combined, lead to re-identification. How are you going to get more anonymous data? Practically speaking if your target has such poor opsec that he's hemorrhaging bits of data, you probably don't need this attack to deanonymize them.

>How are you going to get more anonymous data?

All over the place? Your comment history here (and mine!) is full of data. Each piece alone isn't identifying, but there's a good chance that in aggregate it is.

If you share that username on discord/twitter/reddit/steam/whatever, that's even more data. If you reference old accounts anywhere, you guessed it, even more.

>you probably don't need this attack to deanonymize them

My comment wasn't necessarily specific to this attack, just noting that this attack can be an additional piece of data in the chain of re-identification.

You've gone from "not convinced on the real world applications here" to "how are you going to get more anonymous data". If we assume that you can get some data somewhere (a small list of example sources above), can we agree that there is, possibly, a real world application?

Re: 0-click deanonymization attack targeting Signal, Discord, other platforms

#258

Earlier quoted context omitted.

> "deanonymization" is stretching the definition of the word, along with "grab the user's location", as it isn't anything near precise. You'd think so, but you would be surprised how quickly this adds up to other details people share, like "oh I just drove 15 minutes to get Starbucks" or something to that effect, small things that eventually add up to a precise location over time.

> you would be surprised how quickly this adds up Yes, but if social engineering is involved and tracing back through user conversations across a platform, it's hardly a vulnerability, let alone one deserving of a bounty. The way this is currently functioning is intended functionality, and can be further locked down depending on the user's threat model. This can essentially be classified as opsec failure for the Sign…

This is all the classic dismissals of security issues, including blaming the user.

> opsec failure for the Signal user

Signal's mission is to provide security for users who don't know the word 'opsec'.

Re: 0-click deanonymization attack targeting Signal, Discord, other platforms

#259

Earlier quoted context omitted.

"Near a user" is also a big assumption. I'm ~200 miles to ORD and ~500 to IAD, but my ISP's peering & upstream arrangements mean Cloudflare serves my traffic 700 miles from DFW. But, at the same time: Cloudflare isn't going to serve me a cache from Seattle, Manchester, or Tokyo. Pinning down an unknown Signal user to even a rough geographic location is an important bit of metadata that could combine to unmask an indi…

I doubt how useful it would be as an attack. As a single point of info it tells you next to nothing. As part of a composition of other indicators it would be the weak link in the chain probably just causing noise for the not un-likly scenario where the person you're targeting is using a VPN. If it was any less specific we'd be talking about a deanonymization attack that outs whether or not a target is still on Earth.

Oh, this attack would be a useful tool for e.g., identifying whistleblowers that travel a lot (e.g., in academia, military). If you know their Signal ID, you could send them images from time to time and then compare their coarse locations with travel information for a number of suspects.

Re: 0-click deanonymization attack targeting Signal, Discord, other platforms

#260

Is he just 15? The level of technical details, and this part is not that simple: “quickly patched the Signal desktop app to remove SSL pinning and configured Burp to intercept and view HTTP requests/responses sent through the app”

You’d be surprised at how adept the younger generation can be, especially those who’ve grown up with technology. As tech evolves, so do they. There are kids who genuinely apply themselves, and because they’ve been immersed in this environment, it’s practically second nature to them. I remember the late 1990s: I was young, but more than anything, I was curious about how things worked, I had the luxury of time, and access to technology to explore it. I started coding in C++ when I was around 13, and honestly, I still feel like I started too late.
Post reply on HN