This is just the fundamental way the internet works, and is the reason that anonymizing proxies like Tor exist. If you don’t want people to be able to detect your rough geographic location, you should be using a proxy to hide it. For everybody else, knowing the edge server you are closest to is really not a threat.
0-click deanonymization attack targeting Signal, Discord, other platforms
261–270 of 474 posts
Re: 0-click deanonymization attack targeting Signal, Discord, other platforms
#262Earlier quoted context omitted.
You could have it so both people have to add each other before there's any indication that either person added the other. No extra work for person A, and the work for person B is just what person A had to do anyway.
This is mostly unusable for what should be obvious reasons.
Re: 0-click deanonymization attack targeting Signal, Discord, other platforms
#263So if you send a picture to a Signal user, it's retrieved via cloudflare, and cached in a data center near that user; now you can look up the cache status and find the data center used. I'd say "deanonymization" is stretching it, unless the user is in the middle of nowhere (no other users near the data center). But interesting writeup anyway.
Re: 0-click deanonymization attack targeting Signal, Discord, other platforms
#264Not sure why so many top comments dismiss the severity of this. This is just exactly the type of attack that give law enforcement or a malicious actor a way to establish proof of whereabouts.
First dismiss it and see if the problem is still there in the morning. Hope that before then, someone finds a reason it's not a problem. Anyone?
Re: 0-click deanonymization attack targeting Signal, Discord, other platforms
#265So if you send a picture to a Signal user, it's retrieved via cloudflare, and cached in a data center near that user; now you can look up the cache status and find the data center used. I'd say "deanonymization" is stretching it, unless the user is in the middle of nowhere (no other users near the data center). But interesting writeup anyway.
Re: 0-click deanonymization attack targeting Signal, Discord, other platforms
#266Clever finding but the title does no justice to the actual attack. Even a bare minimum threat model requires a user to use VPN or Tor which completely eliminates your "0day". Signal rightfully declined your report because it's only job is to provide secure communication
Re: 0-click deanonymization attack targeting Signal, Discord, other platforms
#267why is the picture not simply cached near the sender as opposed to the receiver? is there any good reason for deciding this way on the part of Signal et al?
Re: 0-click deanonymization attack targeting Signal, Discord, other platforms
#268Earlier quoted context omitted.
Hello, I'm an organizer for a system to coordinate multiple mutual aid networks, many of which are only organizing by Signal & Protonmail exclusively because they think they're secure and private. People who are doing work to help people in ways the state tries to prevent (like giving people food) rely on this tech. These are the same groups who were able to mobilize so quickly to respond to the LA fires, but the Red…
What groups did the police and Red Cross shut down? Any links?
The powerful entities tend to prohibit relief to the oppressed side, even making it illegal.
Re: 0-click deanonymization attack targeting Signal, Discord, other platforms
#269Congrats on finding this. Very impressive for a 15-year-old! The section "How to Protect Yourself" is lacking. Step 1. Don't receive this information in the push message. Only send the fact that there is something waiting for you in the app. Chances are there are other vulnerabilities that compromise the end-to-end encryption guarantees provided by the app (and only by the app). In Signal on iOS: Click on your icon i…
Step 2: If you use Discord, don't allow invites from _anyone_. Its quite bizarre why social media apps allow anonymous people to interact with you. 99% of the conversation I have is with people that I roughly know.
Re: 0-click deanonymization attack targeting Signal, Discord, other platforms
#270Congrats on finding this. Very impressive for a 15-year-old! The section "How to Protect Yourself" is lacking. Step 1. Don't receive this information in the push message. Only send the fact that there is something waiting for you in the app. Chances are there are other vulnerabilities that compromise the end-to-end encryption guarantees provided by the app (and only by the app). In Signal on iOS: Click on your icon i…
Step 2: If you use Discord, don't allow invites from _anyone_. Its quite bizarre why social media apps allow anonymous people to interact with you. 99% of the conversation I have is with people that I roughly know.
Bit strange to attribute this to 'social media apps', isn't it? I'm interacting with an anonymous person right now. Most platforms allow it, including the older ones (i.e., IRC)