Live data from Hacker News

0-click deanonymization attack targeting Signal, Discord, other platforms

gist.github.com

281–290 of 474 posts

Re: 0-click deanonymization attack targeting Signal, Discord, other platforms

#281
post #222

Earlier quoted context omitted.

Every little bit helps. You can plot the timestamps of every message, read receipt and emoji reaction, which gives you the timezone and hints at work schedule, commute duration and vacations. Often people will post photos or have profile pictures. Say you have a photo taken at a random mcdonalds. That'd be 36'000 locations. Imagine cloudflare location and timezone help you narrow it down to new mexico. That's 80 loca…

>Often people will post photos or have profile pictures. >Say you have a photo taken at a random mcdonalds. That'd be 36'000 locations. Imagine cloudflare location and timezone help you narrow it down to new mexico. That's 80 locations. Small enough that you can look at every single one using street view and check where the photo actually was taken. Sounds like the bigger opsec failure is posting the pictures, and th…

> Sounds like the bigger opsec failure is posting the pictures, and the leaking the cloudflare POP only makes the search slightly easier.

I would not define 3 orders of magnitude as "slightly easier".

Re: 0-click deanonymization attack targeting Signal, Discord, other platforms

#284
post #234

Why has Signal even enabled caching for those URLs? The most common case is going to be that the attachment is downloaded once, and that's it. I would even expect that Signal wouldn't allow you to download it more than once, and would immediately delete it after the first successful download. Well, ok, maybe the client fails mid-way through, so allow some grace period for a re-download. But I can't imagine that would…

Signal's default setup is more usability focused while supporting E2E, and less about tinfoil hat threat models about being present on a continent you're a citizen of.

The items you mentioned can essentially be configured, for those that want the insane level of privacy / security. Messages can be auto-deleted 30 seconds after being seen, a proxy can be configured to route all your traffic through it, and tons of other things can be done to customize it more to the user's liking.

I'd imagine they're caching it because of egress costs. File attachments, voice mail, video, etc. can all add up.

Re: 0-click deanonymization attack targeting Signal, Discord, other platforms

#285

Earlier quoted context omitted.

Step 2: If you use Discord, don't allow invites from _anyone_. Its quite bizarre why social media apps allow anonymous people to interact with you. 99% of the conversation I have is with people that I roughly know.

Just don't use it. Expecting privacy and security from a literal keylogger. Who in their right mind uses a plain-text messaging app in 2025?

How is Discord a key logger?

Re: 0-click deanonymization attack targeting Signal, Discord, other platforms

#286
post #251

So if you send a picture to a Signal user, it's retrieved via cloudflare, and cached in a data center near that user; now you can look up the cache status and find the data center used. I'd say "deanonymization" is stretching it, unless the user is in the middle of nowhere (no other users near the data center). But interesting writeup anyway.

Combined with other information, it may identify someone reliably, just like you can with zip code, age and gender. For example, if you know this person is part of a group with members in several locations, or if you can corroborate someone's movements, etc. For example, imagine someone suspected of sharing sensitive information with a journalist. They might have a short list of suspects, and use this technique to co…

Or you want to find a specific journalist, and you find out that they just arrived to a certain city, and there are only three hotels in that city...

Re: 0-click deanonymization attack targeting Signal, Discord, other platforms

#289

Cool writeup with some interesting techniques and approaches! I'll echo the other comments and say "deanonymization" is stretching the definition of the word, along with "grab the user's location", as it isn't anything near precise. 150 miles is approx. a 2-hour drive on the highway from Atlanta, GA to Augusta, GA. In that radius, there's probably 700,000+ people. I do think the auto-retrieve attachment feature of Si…

You can disable the auto-download. Settings > Data and storage > Media auto-download, you can choose what to auto download for mobile data/wifi/roaming.

hmm. I find the auto-download setting in the mobile app but not on desktop (mac). anyone know?
Post reply on HN