0-click deanonymization attack targeting Signal, Discord, other platforms
41–50 of 474 posts
Re: 0-click deanonymization attack targeting Signal, Discord, other platforms
#42Earlier quoted context omitted.
Nothing stops Cloudflare from inspecting the file contents, or using a hash to distinguish between identically-sized files. The only reason we assume they don't do this is because it's a waste of resources for no good reason. But what if somebody gave them a good reason?
Aren’t the files end-to-end encrypted? How would they inspect the files?
Re: 0-click deanonymization attack targeting Signal, Discord, other platforms
#43Unless I'm missing something, this seems like an incredibly long winded way to check the users IP location? For example, connecting to a VPN and checking https://cloudflare.com/cdn-cgi/trace gives me `colo:CPH` (Copenhagen) which is far from my nearest CF datacenter (geographically), closer to the IP location from my VPN provider (Oslo) but still not particularly close? If I don't use a VPN, I don't even get the capi…
As a piece of data alone, the results are probably not of significant use.
The real-world application (and potential danger) is when this data is combined with other data. De-anonymization techniques using sparse datasets has been an active area of research for at least 15 years and it is often surprising to people how much can be gleaned from a few pieces of seemingly unconnected data.
Re: 0-click deanonymization attack targeting Signal, Discord, other platforms
#44Earlier quoted context omitted.
Nothing stops Cloudflare from inspecting the file contents, or using a hash to distinguish between identically-sized files. The only reason we assume they don't do this is because it's a waste of resources for no good reason. But what if somebody gave them a good reason?
Aren’t the files end-to-end encrypted? How would they inspect the files?
Re: 0-click deanonymization attack targeting Signal, Discord, other platforms
#45> it's possible for an attacker to run a cache geolocation attack to find out which local datacenter they're near--similar to how law enforcement track mobile devices through cell phone towers. very much disagree on this, they track mobile devices through your connection strength to multiple cellular towers while this attack proves which singular datacenter the victim is nearest. Don’t get me wrong the write up is re…
> Don’t get me wrong the write up is really interesting but it does feel like the author is a bit of a sensationalist. They claim to be 15 years old. Cut them some slack.
> Joined November 2017
so likely a bit older :)
Re: 0-click deanonymization attack targeting Signal, Discord, other platforms
#46Unless I'm missing something, this seems like an incredibly long winded way to check the users IP location? For example, connecting to a VPN and checking https://cloudflare.com/cdn-cgi/trace gives me `colo:CPH` (Copenhagen) which is far from my nearest CF datacenter (geographically), closer to the IP location from my VPN provider (Oslo) but still not particularly close? If I don't use a VPN, I don't even get the capi…
Re: 0-click deanonymization attack targeting Signal, Discord, other platforms
#47Earlier quoted context omitted.
Aren’t the files end-to-end encrypted? How would they inspect the files?
Last time I used Cloudflare I think their settings default to only "Origin SSL/TLS" (or whatever they call it), which wouldn't encrypt anything between Cloudflare and the origin, it would only encrypt data between Cloudflare and the end-user/browser.
Re: 0-click deanonymization attack targeting Signal, Discord, other platforms
#48What's old is new. Does anyone remember the forum signatures that would display the viewers IP address and location on a little wooden signpost held up by a troll-looking creature? https://cdn.geekzone.co.nz/images/forums/danasoftcache.jpg
Re: 0-click deanonymization attack targeting Signal, Discord, other platforms
#49"Signal instantly dismissed my report" "Telegram, another privacy-focused application, is completely invulnerable to this attack" "Discord […] citing this as a Cloudflare issue other consumers are also vulnerable to" "Cloudflare ended up completing patching the bug" I wish Signal would react differently. I still remember the bubble color controversy when they changed their mind after the backlash and not before. :-)
Re: 0-click deanonymization attack targeting Signal, Discord, other platforms
#50[flagged]