Live data from Hacker News

0-click deanonymization attack targeting Signal, Discord, other platforms

gist.github.com

381–390 of 474 posts

Re: 0-click deanonymization attack targeting Signal, Discord, other platforms

#381

So if you send a picture to a Signal user, it's retrieved via cloudflare, and cached in a data center near that user; now you can look up the cache status and find the data center used. I'd say "deanonymization" is stretching it, unless the user is in the middle of nowhere (no other users near the data center). But interesting writeup anyway.

> cached in a data center near that user

Not necessarily. Cloudflare is very upfront that they do not cache everything, and the time things are cached can vary greatly.

The kid keeps talking about "deanonymization" and he has no idea what the term actually means.

Re: 0-click deanonymization attack targeting Signal, Discord, other platforms

#382
post #8

So if you send a picture to a Signal user, it's retrieved via cloudflare, and cached in a data center near that user; now you can look up the cache status and find the data center used. I'd say "deanonymization" is stretching it, unless the user is in the middle of nowhere (no other users near the data center). But interesting writeup anyway.

It gets more interesting when you think about the impact on groups. Sending an image to a group is enough for all devices associated with that group to be identifiable from CloudFlare's side, who additionally see a giant chunk of unencrypted traffic from the same client addresses going to other web sites. Given Cloudflare's less-than-straight approach to sales, it is astonishing the words "secure" and "Signal" ever a…

> , it is astonishing the words "secure" and "Signal" ever appear in the same sentence.

You misspelled "I do not understand what end to end encryption means"

Re: 0-click deanonymization attack targeting Signal, Discord, other platforms

#383

So if you send a picture to a Signal user, it's retrieved via cloudflare, and cached in a data center near that user; now you can look up the cache status and find the data center used. I'd say "deanonymization" is stretching it, unless the user is in the middle of nowhere (no other users near the data center). But interesting writeup anyway.

For that reason that's why federated setup such as matrix are better. It is much harder to deanonymiza a set of users on different servers in group chat.

Re: 0-click deanonymization attack targeting Signal, Discord, other platforms

#385
post #12

"Signal instantly dismissed my report" "Telegram, another privacy-focused application, is completely invulnerable to this attack" "Discord […] citing this as a Cloudflare issue other consumers are also vulnerable to" "Cloudflare ended up completing patching the bug" I wish Signal would react differently. I still remember the bubble color controversy when they changed their mind after the backlash and not before. :-)

Signal is likely funded by the CIA and other intelligence actors:

https://yasha.substack.com/p/signal-is-a-government-op-85e

https://www.kitklarenberg.com/p/signal-facing-collapse-after...

https://www.city-journal.org/article/signals-katherine-maher...

https://drewdevault.com/2018/08/08/Signal.html

https://bigleaguepolitics.com/court-docs-show-fbi-can-interc...

Re: 0-click deanonymization attack targeting Signal, Discord, other platforms

#386

So if you send a picture to a Signal user, it's retrieved via cloudflare, and cached in a data center near that user; now you can look up the cache status and find the data center used. I'd say "deanonymization" is stretching it, unless the user is in the middle of nowhere (no other users near the data center). But interesting writeup anyway.

[dead]

Re: 0-click deanonymization attack targeting Signal, Discord, other platforms

#387

So if you send a picture to a Signal user, it's retrieved via cloudflare, and cached in a data center near that user; now you can look up the cache status and find the data center used. I'd say "deanonymization" is stretching it, unless the user is in the middle of nowhere (no other users near the data center). But interesting writeup anyway.

"Near a user" is also a big assumption. I'm ~200 miles to ORD and ~500 to IAD, but my ISP's peering & upstream arrangements mean Cloudflare serves my traffic 700 miles from DFW. But, at the same time: Cloudflare isn't going to serve me a cache from Seattle, Manchester, or Tokyo. Pinning down an unknown Signal user to even a rough geographic location is an important bit of metadata that could combine to unmask an indi…

[deleted]

Re: 0-click deanonymization attack targeting Signal, Discord, other platforms

#389
post #366

Earlier quoted context omitted.

I would guess some are just jealous of his age, but some do find the claim of de anonymizing to simply be overblown given it doesn't tell you nearly enough to find anyone except in very niche cases. This "attack" is easily defeated with a VPN or living in any major city.

You don't need to live in a major city. Cloudflare is never going to set up a caching proxy for a hamlet in the desert; you'll always be part of a huge group that a given caching proxy serves. The attacker can be happy if they can narrow the recipient's location down as much as to a single country

Posters are missing the point by projecting themselves into the scenario. Yes, it probably isn't a concern for someone living in the US or the EU. The calculus is different if you live in a smaller country, a politically sensitive area or are involved in activism against an authoritarian state.

Even for individuals in those large, developed suprastates, it opens the door for catfishing and other social engineering approaches.

Re: 0-click deanonymization attack targeting Signal, Discord, other platforms

#390

Earlier quoted context omitted.

"Near a user" is also a big assumption. I'm ~200 miles to ORD and ~500 to IAD, but my ISP's peering & upstream arrangements mean Cloudflare serves my traffic 700 miles from DFW. But, at the same time: Cloudflare isn't going to serve me a cache from Seattle, Manchester, or Tokyo. Pinning down an unknown Signal user to even a rough geographic location is an important bit of metadata that could combine to unmask an indi…

Note that CF will also route relative to the sites' plan. Enterprise sites are almost always routed to the closest DC, while if that DC is overloaded then lower tier websites, typically just Free sites, will get routed elsewhere (I suppose this is achieved via different anycast ranges where a specific DC is excluded). Although Discord, Signal, etc are almost certainly Enterprise sites. I have this old site to test th…

WTF? the trace endpoint allows CORS from any origin?!? Why?!
Post reply on HN