Live data from Hacker News

0-click deanonymization attack targeting Signal, Discord, other platforms

gist.github.com

451–460 of 474 posts

Re: 0-click deanonymization attack targeting Signal, Discord, other platforms

#451
post #342

I'm a bit at a loss there. Has _anyone_ ever considered Signal to be anonymous? Or Discord? If so, I have bad news: they are not anonymous. At all. Not even slightly anonymous. Nor did they ever claim to be, they only claim to not be able to read your messages (Signal claims that, I don't know about Discord, I doubt it). And that claim has flaws (sure the crypto is sound but have you thoroughly reviewed and compiled…

People do use Signal and Telegram* in settings where anonymity matters. Sure they aren't meant for that, but there's no other widely-understood solution, and most of the time it's good enough for them.

* Funny enough, not vulnerable this time because they use an in-house protocol, which is maybe even worse.

Re: 0-click deanonymization attack targeting Signal, Discord, other platforms

#452

Clever finding but the title does no justice to the actual attack. Even a bare minimum threat model requires a user to use VPN or Tor which completely eliminates your "0day". Signal rightfully declined your report because it's only job is to provide secure communication

Typical mobile user with a VPN is still vulnerable as far as I can tell, because they may be disconnected while displaying a push notification, but feel free to prove me wrong: https://news.ycombinator.com/item?id=42786466

Re: 0-click deanonymization attack targeting Signal, Discord, other platforms

#453
post #295

Earlier quoted context omitted.

Or you want to find a specific journalist, and you find out that they just arrived to a certain city, and there are only three hotels in that city...

That doesn't tell you whether that journalist is investigating you. Identifying them as the recipient of a Signal message from a suspect is valuable information.

I mean to assassinate

Re: 0-click deanonymization attack targeting Signal, Discord, other platforms

#454
post #411

Earlier quoted context omitted.

Given the twitter account was made in 2017, they would have been eight: https://x.com/hackermondev And that bug report to Adobe was made when they would have been five years old: https://hackerone.com/daniel?type=user

He'd be 8 when he made the Twitter account, not when he discovered that exploit. Pretty sure there are tons of 8yos with Twitter accounts.

[deleted]

Re: 0-click deanonymization attack targeting Signal, Discord, other platforms

#455
post #342

I'm a bit at a loss there. Has _anyone_ ever considered Signal to be anonymous? Or Discord? If so, I have bad news: they are not anonymous. At all. Not even slightly anonymous. Nor did they ever claim to be, they only claim to not be able to read your messages (Signal claims that, I don't know about Discord, I doubt it). And that claim has flaws (sure the crypto is sound but have you thoroughly reviewed and compiled…

People do use Signal and Telegram* in settings where anonymity matters. Sure they aren't meant for that, but there's no other widely-understood solution, and most of the time it's good enough for them. * Funny enough, not vulnerable this time because they use an in-house protocol, which is maybe even worse.

[deleted]

Re: 0-click deanonymization attack targeting Signal, Discord, other platforms

#457
post #380

Earlier quoted context omitted.

> Do you think a large proportion of Signal users also use VPNs? It is feasible to consider that interesting Signal users mostly use VPN as an extra protection layer.

Being 'interesting' doesn't make you more likely to understand VPNs and opsec. I expect it makes you more likely to try, but there's a good chance of doing it ineffectively.

I disagree, it does significantly increase the likeliness. Like having cancer makes you significantly more likely to know a lot of medical facts about cancer.

If you fear for your life you are much more likely to have spent time researching how to protect yourself digitally.

Re: 0-click deanonymization attack targeting Signal, Discord, other platforms

#458
post #380

Earlier quoted context omitted.

Being 'interesting' doesn't make you more likely to understand VPNs and opsec. I expect it makes you more likely to try, but there's a good chance of doing it ineffectively.

Fair point. But there are lot of educational resources for whistleblowers and others. OPSEC is crucial nowadays.

There's a lot of nonsense too. In another HN thread, someone was explaining to me that email is more secure than Signal, and desktops more secure than phones - and they had a link to someone's blog to prove it.

That's a HN reader. For the non-technical, it is a minefield.

Re: 0-click deanonymization attack targeting Signal, Discord, other platforms

#459
post #295

Earlier quoted context omitted.

That doesn't tell you whether that journalist is investigating you. Identifying them as the recipient of a Signal message from a suspect is valuable information.

I mean to assassinate

Why are we talking about assassination?

Re: 0-click deanonymization attack targeting Signal, Discord, other platforms

#460

So if you send a picture to a Signal user, it's retrieved via cloudflare, and cached in a data center near that user; now you can look up the cache status and find the data center used. I'd say "deanonymization" is stretching it, unless the user is in the middle of nowhere (no other users near the data center). But interesting writeup anyway.

[dupe]

[dead]
Post reply on HN