Live data from Hacker News

0-click deanonymization attack targeting Signal, Discord, other platforms

gist.github.com

441–450 of 474 posts

Re: 0-click deanonymization attack targeting Signal, Discord, other platforms

#441

Earlier quoted context omitted.

Their twitter says > Joined November 2017 so likely a bit older :)

Ah, that's true. They even have HackerOne activity from 8 years ago: https://hackerone.com/daniel/hacktivity?type=user So either they lied about their age then in order to join social media and they're some sort of child prodigy... or they're lying now.

H1 activity at 8 is pretty crazy but yeah, I never put real information unless it's financial/stuff I care about

Benjamin Dover, 1600 Pennsylvania Ave, born in 1999 ;)

Re: 0-click deanonymization attack targeting Signal, Discord, other platforms

#442
post #148

Earlier quoted context omitted.

Exactly. Especially when considering that Signal was often advertised as that *one* privacy friendly open-source messaging solution in a world dominated by data-collecting demons like WhatsApp, etc. I don't think even WhatsApp let's such status details leak; notwithstanding whatever they might be doing with the user data on the backend.

I can send a link in Whatsapp to a domain I control and track if clicked. How is that different?

The difference is that your target needs to actually click it. For this, they don't.

Re: 0-click deanonymization attack targeting Signal, Discord, other platforms

#443
post #140

What is the benefit of caching images in a cdn for Signal? Assuming local client-side caching, the total number of requests for that resource should be very small, probably one in the vast majority of cases. On an unrelated note, it seems like CloudFront could very easily fix this by not returning the cf-ray header, or at least having an option for the customer to remove it. Although, it might still be possible to ge…

So that law enforcement can ask Cloudflare for the IP logs... Signal is a joke. https://simplex.chat/

Signal claims to be a private, not anynomous, chat application.

Theirt defaults are set so they can get mass market addoption, whilst beeing a big step up in privacy compared to the usual players in the space (like whatsapp and telegram). You simply won't be able to get the average user on apps that make use more complicated and apps like simplex doe exactly that.

If you want Signal to be more secure, you can circumvent this attack vector by disableing auto downloads for media.

I'm not saying Signal is perfect, there has been a bunch to critisize over the years.

But why argue about use cases they never claimed to solve?

Re: 0-click deanonymization attack targeting Signal, Discord, other platforms

#444
post #380

Earlier quoted context omitted.

> Do you think a large proportion of Signal users also use VPNs? It is feasible to consider that interesting Signal users mostly use VPN as an extra protection layer.

Being 'interesting' doesn't make you more likely to understand VPNs and opsec. I expect it makes you more likely to try, but there's a good chance of doing it ineffectively.

Fair point. But there are lot of educational resources for whistleblowers and others. OPSEC is crucial nowadays.

Re: 0-click deanonymization attack targeting Signal, Discord, other platforms

#446
post #156

Earlier quoted context omitted.

What groups did the police and Red Cross shut down? Any links?

In any geopolitical crisis, you tend to have victims on both sides be prevented from getting relief, except when the one side is imperial. The powerful entities tend to prohibit relief to the oppressed side, even making it illegal.

I’m thinking as well more “mundane” things as well, like red states with “charitable feeding” laws that in effect make it illegal to feed the homeless without large amounts of red tape.

But, truly, I think you’re right to highlight wars.

https://www.salon.com/2023/08/07/criminalizing-the-samaritan...

Re: 0-click deanonymization attack targeting Signal, Discord, other platforms

#447
post #146

Cool! Contrary to some of the other posters I think this definitely counts as deanonymization, or at least is close enough. How anonymous would satoshi be today if we had his location to within 250 miles? Repeated applications of this attack (maybe disguised somehow?) could let you track someone’s travel over time, and it is usually only takes 4-5 zip code sized locations to uniquely identify someone.

The counter point is that anyone who cares about being anonymous is using methods to disguise their identity that cannot be compromised by this attack, e.g: a VPN. Plus, there are much more effective versions of this attack, like sending a link to an endpoint that you control -- getting someone to click a link isn't hard if you're considered trustworthy enough to send them notifications. And less technical versions,…

> The counter point is that anyone who cares about being anonymous is using methods to disguise their identity

https://news.ycombinator.com/item?id=42784398

Re: 0-click deanonymization attack targeting Signal, Discord, other platforms

#448
post #376

I guess I'm not so "crazy" for funneling all my Android's outbound traffic through a VPN that does two hops.

Whether that's crazy depends on your threat model. If there's no reason, it could still be crazy in the sense of protecting from an irrational fear. If you communicate with people or organisations who shouldn't know your location, it makes sense. It depends

If you've ever been stalked by a crazy ex-girlfriend who is from a very rich family, you'll probably feel a little "paranoid" or whatever.

I was already on the "I just want to be left alone" vibe generally before all that happened to me, so I just carried on as usual.

Re: 0-click deanonymization attack targeting Signal, Discord, other platforms

#450
post #411

Note: this person is the same 15-year old who found the Zendesk Slack takeover exploit a few months ago [1]. [1]: https://news.ycombinator.com/item?id=41818459

Given the twitter account was made in 2017, they would have been eight: https://x.com/hackermondev And that bug report to Adobe was made when they would have been five years old: https://hackerone.com/daniel?type=user

He'd be 8 when he made the Twitter account, not when he discovered that exploit. Pretty sure there are tons of 8yos with Twitter accounts.
Post reply on HN