Live data from Hacker News

0-click deanonymization attack targeting Signal, Discord, other platforms

gist.github.com

401–410 of 474 posts

Re: 0-click deanonymization attack targeting Signal, Discord, other platforms

#401

This is just the fundamental way the internet works, and is the reason that anonymizing proxies like Tor exist. If you don’t want people to be able to detect your rough geographic location, you should be using a proxy to hide it. For everybody else, knowing the edge server you are closest to is really not a threat.

No, it isn't. This is Cloudflare passing exposing metadata when it really shouldn't. Having a configuration option or a origin response header akin to CloudflareCache: private or something is trivial for them to implement.

The same information would then be available in the timing, but given the distributed nature here, that would be a lot harder to pull off.

Re: 0-click deanonymization attack targeting Signal, Discord, other platforms

#402
post #365

Earlier quoted context omitted.

If I can send you a link and be guaranteed that you click on it. Then that’s definitely a security issue.

Then it's a good thing that this isn't being claimed

The comment says: Every time you click on a link your external IP addresses is exposed, is this a vulnerability? Being online without a VPN / proxy is inherent consent to have your external IP & other required items to be shared with services / middlemen.

The fact that a user's IP is exposed when they click on a link is only relevant to the original post if a user would do this automatically and without realizing. The original post alleges that they can send someone a message on Signal and have the user automatically and somewhat unknowingly load a resource from a server. Sure, the author doesn't claim they have much control over the resource or the server, but they do show how you can check which server the user accessed and how that leaks information about the location of the user to a certain extent.

Re: 0-click deanonymization attack targeting Signal, Discord, other platforms

#404
I think all these things are absolutely ridiculous.

I use alpine (the email client, not the Linux distro). Before that, I used pine.

Every single thing that gets loaded from anywhere on the Internet has to be the result of an action that I take. Nothing ever gets loaded automatically. I get to choose if I load the thing using the server that I'm connected to, or if I load it directly on my local machine. I know the implications of each.

The fact that programs, particularly ones that are supposed to be for the security minded like Signal, load anything by default, automatically, is just, well, naive.

I can't be the only person who thinks that people who don't think these things through shouldn't be working on apps and email clients. Sure, people would have a cow if their email client didn't load every frigging thing and run remote Javascript and so on, but in Signal? Really?

(end rant)

I see that this can be turned off. I will now tell everyone I know that uses Signal that this should, in fact, be turned off.

Re: 0-click deanonymization attack targeting Signal, Discord, other platforms

#405
post #117
post #12

"Signal instantly dismissed my report" "Telegram, another privacy-focused application, is completely invulnerable to this attack" "Discord […] citing this as a Cloudflare issue other consumers are also vulnerable to" "Cloudflare ended up completing patching the bug" I wish Signal would react differently. I still remember the bubble color controversy when they changed their mind after the backlash and not before. :-)

>"Signal instantly dismissed my report" >I wish Signal would react differently. I still remember the bubble color controversy when they changed their mind after the backlash and not before. :-) Can you blame them though? They're a non-profit with limited manpower and resources. There's quite a lot of cranks in the security field, and as many people have echoed in this thread, the bug report is rather sensationalist.…

[deleted]

Re: 0-click deanonymization attack targeting Signal, Discord, other platforms

#406
post #359

Earlier quoted context omitted.

Oh, this attack would be a useful tool for e.g., identifying whistleblowers that travel a lot (e.g., in academia, military). If you know their Signal ID, you could send them images from time to time and then compare their coarse locations with travel information for a number of suspects.

I believe they'd have to accept the chat request before any images would be loaded? Looking at the app options it seems to be possible to disable media auto-download entirely; there's tickboxes for Images/Audio/Video/Documents via Mobile Data/Wi-Fi/Roaming.

Yes, I agree. This attack won't work on competent / paranoid people. What I had in mind when writing the comment: a whistleblower who wants to inform the press about illegal practices in their company and installed Signal to communicate anonymously with journalists. Somehow, a detective working for the company got their Signal ID and contacted them, impersonating a journalist.

Re: 0-click deanonymization attack targeting Signal, Discord, other platforms

#407

So many comments get caught on the wording 'deanonymization'. Is there a standardized definition of 'deanonymization' accross industry experts, privacy-conscious people and hackers? For many commenters, it looks like deanonymization means unveiling highly sensitive info like name, address, email, etc. For privacy-conscious individuals and hackers, it looks like it means 'revealing a data point that shouldn't be revea…

As you say, it depends on the person but I think for most people an acceptable definition is "deanonymization reveals PII". What qualifies as PII depends on the context/jurisdiction but typically an IP address would be considered PII whereas country (or a similar broad region) would not.

https://en.wikipedia.org/wiki/Personal_data

Re: 0-click deanonymization attack targeting Signal, Discord, other platforms

#408
post #146

Cool! Contrary to some of the other posters I think this definitely counts as deanonymization, or at least is close enough. How anonymous would satoshi be today if we had his location to within 250 miles? Repeated applications of this attack (maybe disguised somehow?) could let you track someone’s travel over time, and it is usually only takes 4-5 zip code sized locations to uniquely identify someone.

The counter point is that anyone who cares about being anonymous is using methods to disguise their identity that cannot be compromised by this attack, e.g: a VPN. Plus, there are much more effective versions of this attack, like sending a link to an endpoint that you control -- getting someone to click a link isn't hard if you're considered trustworthy enough to send them notifications. And less technical versions,…

On iCloud public relay, go to settings and select “use country and time zone” instead of “use general location.”

Now you’re no longer “within 250 miles,” hell my phone geo IPs everywhere from Louisiana to New Jersey , which are not even “in my time zone,” but there you go.

This setting was pissing meta/Facebook off big time because they also couldn’t narrow me down to a precise geographical area, resulting in much nagging and whining about “was this you signing in from [shreveport]?” and frequent account lockouts , password resets, and endless requests to approve my logins from a device that’s already logged in before I finally said to hell with it and deleted FB a few days ago.

I figure if a privacy setting makes meta mad , then it’s .. probably … a good setting. Must really irk them trying to sell location relevant ads when my state changes every other time I unlock my screen.

It’s a combined behavior of using private browsing and refusing to install their app, thereby giving them a permanent supercookie no matter what my IP is, so if you don’t like the sound of this it [might not] affect you if you use their apps. “X” does it too, just look up “inferred identity+ twitter” on google.

I’m editing out a tall claim in the last paragraph of this for some other time when I’m less tired and have sources next time we’re on the subject.

Re: 0-click deanonymization attack targeting Signal, Discord, other platforms

#410

So if you send a picture to a Signal user, it's retrieved via cloudflare, and cached in a data center near that user; now you can look up the cache status and find the data center used. I'd say "deanonymization" is stretching it, unless the user is in the middle of nowhere (no other users near the data center). But interesting writeup anyway.

Did you see the GIF? It's able to triangulate.
Post reply on HN