Live data from Hacker News

0-click deanonymization attack targeting Signal, Discord, other platforms

gist.github.com

41–50 of 474 posts

Re: 0-click deanonymization attack targeting Signal, Discord, other platforms

#42
post #25

Earlier quoted context omitted.

Nothing stops Cloudflare from inspecting the file contents, or using a hash to distinguish between identically-sized files. The only reason we assume they don't do this is because it's a waste of resources for no good reason. But what if somebody gave them a good reason?

Aren’t the files end-to-end encrypted? How would they inspect the files?

yeah, the person you're referring to is confused because the Cloudflare HTTP service terminates TLS and presents a Cloudflare certificate, but that doesn't have anything to do at all with Signal's E2EE which is not based on HTTPS PKI

Re: 0-click deanonymization attack targeting Signal, Discord, other platforms

#43

Unless I'm missing something, this seems like an incredibly long winded way to check the users IP location? For example, connecting to a VPN and checking https://cloudflare.com/cdn-cgi/trace gives me `colo:CPH` (Copenhagen) which is far from my nearest CF datacenter (geographically), closer to the IP location from my VPN provider (Oslo) but still not particularly close? If I don't use a VPN, I don't even get the capi…

>just not convinced on the real world applications here...

As a piece of data alone, the results are probably not of significant use.

The real-world application (and potential danger) is when this data is combined with other data. De-anonymization techniques using sparse datasets has been an active area of research for at least 15 years and it is often surprising to people how much can be gleaned from a few pieces of seemingly unconnected data.

Re: 0-click deanonymization attack targeting Signal, Discord, other platforms

#44
post #25

Earlier quoted context omitted.

Nothing stops Cloudflare from inspecting the file contents, or using a hash to distinguish between identically-sized files. The only reason we assume they don't do this is because it's a waste of resources for no good reason. But what if somebody gave them a good reason?

Aren’t the files end-to-end encrypted? How would they inspect the files?

[deleted]

Re: 0-click deanonymization attack targeting Signal, Discord, other platforms

#45
post #32

> it's possible for an attacker to run a cache geolocation attack to find out which local datacenter they're near--similar to how law enforcement track mobile devices through cell phone towers. very much disagree on this, they track mobile devices through your connection strength to multiple cellular towers while this attack proves which singular datacenter the victim is nearest. Don’t get me wrong the write up is re…

> Don’t get me wrong the write up is really interesting but it does feel like the author is a bit of a sensationalist. They claim to be 15 years old. Cut them some slack.

Their twitter says

> Joined November 2017

so likely a bit older :)

Re: 0-click deanonymization attack targeting Signal, Discord, other platforms

#46

Unless I'm missing something, this seems like an incredibly long winded way to check the users IP location? For example, connecting to a VPN and checking https://cloudflare.com/cdn-cgi/trace gives me `colo:CPH` (Copenhagen) which is far from my nearest CF datacenter (geographically), closer to the IP location from my VPN provider (Oslo) but still not particularly close? If I don't use a VPN, I don't even get the capi…

I guess it can be useful for tracking fugitive political dissidents, terrorists, etc. If you can narrow their location down to 250 miles, it's already very useful information. And without raising any suspicions.

Re: 0-click deanonymization attack targeting Signal, Discord, other platforms

#47
post #40

Earlier quoted context omitted.

Aren’t the files end-to-end encrypted? How would they inspect the files?

Last time I used Cloudflare I think their settings default to only "Origin SSL/TLS" (or whatever they call it), which wouldn't encrypt anything between Cloudflare and the origin, it would only encrypt data between Cloudflare and the end-user/browser.

But the Signal client encrypts images before sending them to the Signal server. If it padded out the images at that point, the images would all be indistinguishable from each other unless Cloudflare were actually able to break the encryption (which would completely undermine the entire security model).

Re: 0-click deanonymization attack targeting Signal, Discord, other platforms

#49
post #12

"Signal instantly dismissed my report" "Telegram, another privacy-focused application, is completely invulnerable to this attack" "Discord […] citing this as a Cloudflare issue other consumers are also vulnerable to" "Cloudflare ended up completing patching the bug" I wish Signal would react differently. I still remember the bubble color controversy when they changed their mind after the backlash and not before. :-)

[deleted]
Post reply on HN