Live data from Hacker News

0-click deanonymization attack targeting Signal, Discord, other platforms

gist.github.com

261–270 of 474 posts

Re: 0-click deanonymization attack targeting Signal, Discord, other platforms

#261

This is just the fundamental way the internet works, and is the reason that anonymizing proxies like Tor exist. If you don’t want people to be able to detect your rough geographic location, you should be using a proxy to hide it. For everybody else, knowing the edge server you are closest to is really not a threat.

People for whom it's a threat don't necessarily understand anonymizing proxies - very few do. Signal is supposed to provide security for those who do not.

Re: 0-click deanonymization attack targeting Signal, Discord, other platforms

#262

Earlier quoted context omitted.

You could have it so both people have to add each other before there's any indication that either person added the other. No extra work for person A, and the work for person B is just what person A had to do anyway.

This is mostly unusable for what should be obvious reasons.

I'm... not actually clear on what those reasons are? For the adder, the experience is exactly the same - the only difference is that there's no longer an adder and an addee - instead there are two adders.

Re: 0-click deanonymization attack targeting Signal, Discord, other platforms

#263

So if you send a picture to a Signal user, it's retrieved via cloudflare, and cached in a data center near that user; now you can look up the cache status and find the data center used. I'd say "deanonymization" is stretching it, unless the user is in the middle of nowhere (no other users near the data center). But interesting writeup anyway.

The real attack is that a law enforcement agency can trivially subpoena CloudFlare with the attachment URL they will hand over the IP address of the recipient of the image along with whatever other requests they made through the CDN which can pretty precisely and rapidly de-anonymize you.

Re: 0-click deanonymization attack targeting Signal, Discord, other platforms

#264
post #204

Not sure why so many top comments dismiss the severity of this. This is just exactly the type of attack that give law enforcement or a malicious actor a way to establish proof of whereabouts.

They dismiss it for the same reason people dismiss disruptive new technology - they are uncomfortable with it. It's a signal (ha) that the threat is very real.

First dismiss it and see if the problem is still there in the morning. Hope that before then, someone finds a reason it's not a problem. Anyone?

Re: 0-click deanonymization attack targeting Signal, Discord, other platforms

#265

So if you send a picture to a Signal user, it's retrieved via cloudflare, and cached in a data center near that user; now you can look up the cache status and find the data center used. I'd say "deanonymization" is stretching it, unless the user is in the middle of nowhere (no other users near the data center). But interesting writeup anyway.

It's leaking so many bits idk what else you would call it, deanonymization isn't a one shot thing and it's a spectrum not a binary outcome

Re: 0-click deanonymization attack targeting Signal, Discord, other platforms

#266

Clever finding but the title does no justice to the actual attack. Even a bare minimum threat model requires a user to use VPN or Tor which completely eliminates your "0day". Signal rightfully declined your report because it's only job is to provide secure communication

Signal is intended not for HN readers, but for ordinary people who don't understand VPNs and Tor.

Re: 0-click deanonymization attack targeting Signal, Discord, other platforms

#267

why is the picture not simply cached near the sender as opposed to the receiver? is there any good reason for deciding this way on the part of Signal et al?

It's cached near the receiver for performance purposes, I assume, the same reason Cloudflare uses geographically local caches.

Re: 0-click deanonymization attack targeting Signal, Discord, other platforms

#268
post #156

Earlier quoted context omitted.

Hello, I'm an organizer for a system to coordinate multiple mutual aid networks, many of which are only organizing by Signal & Protonmail exclusively because they think they're secure and private. People who are doing work to help people in ways the state tries to prevent (like giving people food) rely on this tech. These are the same groups who were able to mobilize so quickly to respond to the LA fires, but the Red…

What groups did the police and Red Cross shut down? Any links?

In any geopolitical crisis, you tend to have victims on both sides be prevented from getting relief, except when the one side is imperial.

The powerful entities tend to prohibit relief to the oppressed side, even making it illegal.

Re: 0-click deanonymization attack targeting Signal, Discord, other platforms

#269
post #11

Congrats on finding this. Very impressive for a 15-year-old! The section "How to Protect Yourself" is lacking. Step 1. Don't receive this information in the push message. Only send the fact that there is something waiting for you in the app. Chances are there are other vulnerabilities that compromise the end-to-end encryption guarantees provided by the app (and only by the app). In Signal on iOS: Click on your icon i…

Step 2: If you use Discord, don't allow invites from _anyone_. Its quite bizarre why social media apps allow anonymous people to interact with you. 99% of the conversation I have is with people that I roughly know.

If you're worried about anonymity and you're using discord, you're failing. It's not made for that.

Re: 0-click deanonymization attack targeting Signal, Discord, other platforms

#270
post #11

Congrats on finding this. Very impressive for a 15-year-old! The section "How to Protect Yourself" is lacking. Step 1. Don't receive this information in the push message. Only send the fact that there is something waiting for you in the app. Chances are there are other vulnerabilities that compromise the end-to-end encryption guarantees provided by the app (and only by the app). In Signal on iOS: Click on your icon i…

Step 2: If you use Discord, don't allow invites from _anyone_. Its quite bizarre why social media apps allow anonymous people to interact with you. 99% of the conversation I have is with people that I roughly know.

> Its quite bizarre why social media apps allow anonymous people to interact with you

Bit strange to attribute this to 'social media apps', isn't it? I'm interacting with an anonymous person right now. Most platforms allow it, including the older ones (i.e., IRC)

Post reply on HN