Earlier quoted context omitted.
I doubt how useful it would be as an attack. As a single point of info it tells you next to nothing. As part of a composition of other indicators it would be the weak link in the chain probably just causing noise for the not un-likly scenario where the person you're targeting is using a VPN. If it was any less specific we'd be talking about a deanonymization attack that outs whether or not a target is still on Earth.
> not un-likly scenario where the person you're targeting is using a VPN Do you think a large proportion of Signal users also use VPNs? I'd expect it would be a higher proportion than the general population but still only a small minority.
0-click deanonymization attack targeting Signal, Discord, other platforms
341–350 of 474 posts
Re: 0-click deanonymization attack targeting Signal, Discord, other platforms
#342At the very best, they are weakly pseudonymous, but that's about it. And yes, loading media by default has always been a staple of applications who prioritize their users' convenience at the expense of some security, a fine choice for the usual threat model of their users. And embedding media in messages has always been a staple of deanonymization attacks.
So ok, the tracking pixel has been shown to still be a relevant technique today, that's nice but not surprising.
If you want to remain anonymous though, don't use Discord or even Signal, and I'd advise against posting on HN either. Maybe, if you automate the pasting of messages (no js!) that has been reworded by a local llm from throwaway accounts through whonix, at random times that can't be correlated to your timezone, you _might_ have your chances. Don't bet on it.
Anonymity does not exist any longer.
Re: 0-click deanonymization attack targeting Signal, Discord, other platforms
#343Earlier quoted context omitted.
Say I send a message to someone who has a phone with push notifications enabled, showing message previews. Will the phone still be connected to the VPN when it wakes up to display the message? Because my iPhone doesn't seem to stay connected to my VPN when it sleeps, at least not reliably. There really should be a "never use the internet without VPN" mode on devices.
Valid point. Afaict, vpns I've used route all network activity regardless of phone state, but that's likely dependant on the service.
So if there's no always-on hardware maintaining that VPN connection, probably the phone is going to wake up without it. And even if it auto-reconnects, it'll probably load stuff before it's connected to the VPN.
Re: 0-click deanonymization attack targeting Signal, Discord, other platforms
#344Earlier quoted context omitted.
Valid point. Afaict, vpns I've used route all network activity regardless of phone state, but that's likely dependant on the service.
I don't see how that can work for the push packet itself, cause I thought that's specially handled by some low-power hardware on the phone while the main parts are shut off. Unless that hardware is also managing the VPN connection, which I doubt. So if there's no always-on hardware maintaining that VPN connection, probably the phone is going to wake up without it. And even if it auto-reconnects, it'll probably load s…
Re: 0-click deanonymization attack targeting Signal, Discord, other platforms
#345Earlier quoted context omitted.
[flagged]
You're making this stuff up. In most threads about Signal, 1-2 commenters appear to post fabricated conspiracist stuff defaming the people who originally worked on Signal --- people extremely well-known to the real-world cryptography engineering community. I don't know why we're so chill about people being defamed here.
Re: 0-click deanonymization attack targeting Signal, Discord, other platforms
#346So if you send a picture to a Signal user, it's retrieved via cloudflare, and cached in a data center near that user; now you can look up the cache status and find the data center used. I'd say "deanonymization" is stretching it, unless the user is in the middle of nowhere (no other users near the data center). But interesting writeup anyway.
"Near a user" is also a big assumption. I'm ~200 miles to ORD and ~500 to IAD, but my ISP's peering & upstream arrangements mean Cloudflare serves my traffic 700 miles from DFW. But, at the same time: Cloudflare isn't going to serve me a cache from Seattle, Manchester, or Tokyo. Pinning down an unknown Signal user to even a rough geographic location is an important bit of metadata that could combine to unmask an indi…
So though this does have implications, the assumptions they utilise, like always, are not universal.
Re: 0-click deanonymization attack targeting Signal, Discord, other platforms
#347It's nice but at most will give you an indication of city. Perhaps together with some additional OSINT you could find the user but you'll need a lot more clues.
Well found though!
Re: 0-click deanonymization attack targeting Signal, Discord, other platforms
#348So if you send a picture to a Signal user, it's retrieved via cloudflare, and cached in a data center near that user; now you can look up the cache status and find the data center used. I'd say "deanonymization" is stretching it, unless the user is in the middle of nowhere (no other users near the data center). But interesting writeup anyway.
There's definitely cases where this is going to be immediately used. Shit, just using it to scrape Cloudflare for additional metadata on everyone from other user table leaks is probably valuable data. Even triangulation over time as they move around is going to get a more precise result. Maybe you find a vulnerability that takes that cloudflare node offline and run it again, repeat until you've got a fairly small radius they could be in.
Re: 0-click deanonymization attack targeting Signal, Discord, other platforms
#349So if you send a picture to a Signal user, it's retrieved via cloudflare, and cached in a data center near that user; now you can look up the cache status and find the data center used. I'd say "deanonymization" is stretching it, unless the user is in the middle of nowhere (no other users near the data center). But interesting writeup anyway.
Yeah and in that case there won't be a data center because who puts one in places without clients nearby? :)
Re: 0-click deanonymization attack targeting Signal, Discord, other platforms
#350Earlier quoted context omitted.
"Near a user" is also a big assumption. I'm ~200 miles to ORD and ~500 to IAD, but my ISP's peering & upstream arrangements mean Cloudflare serves my traffic 700 miles from DFW. But, at the same time: Cloudflare isn't going to serve me a cache from Seattle, Manchester, or Tokyo. Pinning down an unknown Signal user to even a rough geographic location is an important bit of metadata that could combine to unmask an indi…
Cloudflare does serve me from France. When I'm in Australia. (My ISP bought some IP addresses that were original regional France, back in the early 90s.) So though this does have implications, the assumptions they utilise, like always, are not universal.