Live data from Hacker News

0-click deanonymization attack targeting Signal, Discord, other platforms

gist.github.com

431–440 of 474 posts

Re: 0-click deanonymization attack targeting Signal, Discord, other platforms

#431
If I use Signal or Discord to send someone a link to anything hosted on a server controlled by me, provided that the user opens the link, I will get an exact IP address of the user. IP address is much more useful in de-anonymizing the user than the nearest CloudFlare datacenter location.

Re: 0-click deanonymization attack targeting Signal, Discord, other platforms

#432
post #146

Cool! Contrary to some of the other posters I think this definitely counts as deanonymization, or at least is close enough. How anonymous would satoshi be today if we had his location to within 250 miles? Repeated applications of this attack (maybe disguised somehow?) could let you track someone’s travel over time, and it is usually only takes 4-5 zip code sized locations to uniquely identify someone.

... very anonymous because he was most likely using a VPN lmao

Re: 0-click deanonymization attack targeting Signal, Discord, other platforms

#434
post #146

Cool! Contrary to some of the other posters I think this definitely counts as deanonymization, or at least is close enough. How anonymous would satoshi be today if we had his location to within 250 miles? Repeated applications of this attack (maybe disguised somehow?) could let you track someone’s travel over time, and it is usually only takes 4-5 zip code sized locations to uniquely identify someone.

The counter point is that anyone who cares about being anonymous is using methods to disguise their identity that cannot be compromised by this attack, e.g: a VPN. Plus, there are much more effective versions of this attack, like sending a link to an endpoint that you control -- getting someone to click a link isn't hard if you're considered trustworthy enough to send them notifications. And less technical versions,…

Not everyone who indirectly cares about anonymity is an activist who feels they need to go to great lengths to disguise their identity. Sometimes anonymisation is part of a process, and the ability to collect potentially deanonymizing data this way is still a privacy breach.

E.g. imagine sending otherwise anonymised participants in a clinical trial a questionnaire, containing an image. The owner of the image could then partially deanonymize the trial participants. Or voters. Or demonstrators in a rally.

Not everyone who cares about privacy is Edward Snowden material.

Re: 0-click deanonymization attack targeting Signal, Discord, other platforms

#435
post #411

Earlier quoted context omitted.

Given the twitter account was made in 2017, they would have been eight: https://x.com/hackermondev And that bug report to Adobe was made when they would have been five years old: https://hackerone.com/daniel?type=user

I think that's just a quirk of HackerOne's username system. The username daniel was previously owned by another account (now known as daniel-hamid) which submitted a bug to Adobe. If you go through @hackermondev's tweets (starting in 2018) they are without question a kid (making games in Roblox and Minecraft) and then started to show an interest in hacking in 2020 (which lines up with when they created their HackerOn…

Thanks for pointing that out, I missed the username change.

Re: 0-click deanonymization attack targeting Signal, Discord, other platforms

#436

So if you send a picture to a Signal user, it's retrieved via cloudflare, and cached in a data center near that user; now you can look up the cache status and find the data center used. I'd say "deanonymization" is stretching it, unless the user is in the middle of nowhere (no other users near the data center). But interesting writeup anyway.

Why would cloudflare ever operate a data center that only one user at a time is ever near?

Re: 0-click deanonymization attack targeting Signal, Discord, other platforms

#437

So if you send a picture to a Signal user, it's retrieved via cloudflare, and cached in a data center near that user; now you can look up the cache status and find the data center used. I'd say "deanonymization" is stretching it, unless the user is in the middle of nowhere (no other users near the data center). But interesting writeup anyway.

You underestimate the value of this piece of information taken at different times. It can be enough to know in which country a person was yesterday or is today.

Re: 0-click deanonymization attack targeting Signal, Discord, other platforms

#439

If I use Signal or Discord to send someone a link to anything hosted on a server controlled by me, provided that the user opens the link, I will get an exact IP address of the user. IP address is much more useful in de-anonymizing the user than the nearest CloudFlare datacenter location.

That's why this is interesting, it doesn't even require someone to open a link

Re: 0-click deanonymization attack targeting Signal, Discord, other platforms

#440
post #395

So if you send a picture to a Signal user, it's retrieved via cloudflare, and cached in a data center near that user; now you can look up the cache status and find the data center used. I'd say "deanonymization" is stretching it, unless the user is in the middle of nowhere (no other users near the data center). But interesting writeup anyway.

WhatsApp has an option to disable link previews. Surprised signal doesn't have this option. I only message people I know on Signal anyway. Edit: it seems signal does have the option

I had this same thought before reading the article - this isn't about link previews, it's about attachment caching
Post reply on HN