0-click deanonymization attack targeting Signal, Discord, other platforms
431–440 of 474 posts
Re: 0-click deanonymization attack targeting Signal, Discord, other platforms
#432Cool! Contrary to some of the other posters I think this definitely counts as deanonymization, or at least is close enough. How anonymous would satoshi be today if we had his location to within 250 miles? Repeated applications of this attack (maybe disguised somehow?) could let you track someone’s travel over time, and it is usually only takes 4-5 zip code sized locations to uniquely identify someone.
Re: 0-click deanonymization attack targeting Signal, Discord, other platforms
#433Re: 0-click deanonymization attack targeting Signal, Discord, other platforms
#434Cool! Contrary to some of the other posters I think this definitely counts as deanonymization, or at least is close enough. How anonymous would satoshi be today if we had his location to within 250 miles? Repeated applications of this attack (maybe disguised somehow?) could let you track someone’s travel over time, and it is usually only takes 4-5 zip code sized locations to uniquely identify someone.
The counter point is that anyone who cares about being anonymous is using methods to disguise their identity that cannot be compromised by this attack, e.g: a VPN. Plus, there are much more effective versions of this attack, like sending a link to an endpoint that you control -- getting someone to click a link isn't hard if you're considered trustworthy enough to send them notifications. And less technical versions,…
E.g. imagine sending otherwise anonymised participants in a clinical trial a questionnaire, containing an image. The owner of the image could then partially deanonymize the trial participants. Or voters. Or demonstrators in a rally.
Not everyone who cares about privacy is Edward Snowden material.
Re: 0-click deanonymization attack targeting Signal, Discord, other platforms
#435Earlier quoted context omitted.
Given the twitter account was made in 2017, they would have been eight: https://x.com/hackermondev And that bug report to Adobe was made when they would have been five years old: https://hackerone.com/daniel?type=user
I think that's just a quirk of HackerOne's username system. The username daniel was previously owned by another account (now known as daniel-hamid) which submitted a bug to Adobe. If you go through @hackermondev's tweets (starting in 2018) they are without question a kid (making games in Roblox and Minecraft) and then started to show an interest in hacking in 2020 (which lines up with when they created their HackerOn…
Re: 0-click deanonymization attack targeting Signal, Discord, other platforms
#436So if you send a picture to a Signal user, it's retrieved via cloudflare, and cached in a data center near that user; now you can look up the cache status and find the data center used. I'd say "deanonymization" is stretching it, unless the user is in the middle of nowhere (no other users near the data center). But interesting writeup anyway.
Re: 0-click deanonymization attack targeting Signal, Discord, other platforms
#437So if you send a picture to a Signal user, it's retrieved via cloudflare, and cached in a data center near that user; now you can look up the cache status and find the data center used. I'd say "deanonymization" is stretching it, unless the user is in the middle of nowhere (no other users near the data center). But interesting writeup anyway.
Re: 0-click deanonymization attack targeting Signal, Discord, other platforms
#438Re: 0-click deanonymization attack targeting Signal, Discord, other platforms
#439If I use Signal or Discord to send someone a link to anything hosted on a server controlled by me, provided that the user opens the link, I will get an exact IP address of the user. IP address is much more useful in de-anonymizing the user than the nearest CloudFlare datacenter location.
Re: 0-click deanonymization attack targeting Signal, Discord, other platforms
#440So if you send a picture to a Signal user, it's retrieved via cloudflare, and cached in a data center near that user; now you can look up the cache status and find the data center used. I'd say "deanonymization" is stretching it, unless the user is in the middle of nowhere (no other users near the data center). But interesting writeup anyway.
WhatsApp has an option to disable link previews. Surprised signal doesn't have this option. I only message people I know on Signal anyway. Edit: it seems signal does have the option