Live data from Hacker News

0-click deanonymization attack targeting Signal, Discord, other platforms

gist.github.com

461–470 of 474 posts

Re: 0-click deanonymization attack targeting Signal, Discord, other platforms

#461
post #204

Not sure why so many top comments dismiss the severity of this. This is just exactly the type of attack that give law enforcement or a malicious actor a way to establish proof of whereabouts.

I would guess some are just jealous of his age, but some do find the claim of de anonymizing to simply be overblown given it doesn't tell you nearly enough to find anyone except in very niche cases. This "attack" is easily defeated with a VPN or living in any major city.

It's common in our community to be jealous of youth, especially youth with genius, but I believe the github user in TFA is lying. Something about it is off. It also happens in posts here on HN, though.

I think after being exposed to so much internet, you realize how many are simply living a fantasy. In me it provokes a sense of disgust, I see it as part of a broader groomer problem on the internet, but this is a distantly minority take.

Re: 0-click deanonymization attack targeting Signal, Discord, other platforms

#462

Earlier quoted context omitted.

I don't care if users see "my" ipv4 because cgnat. I think i don't care if they can see my ipv6 because each machine gets a /64 to itself, that's the logic, right? But my PBX and my matrix server both use coturn. Our 10 user "private" PBX we have to VPN into a fortigate in a DC to use, but to my understanding, there's literally no way to eavesdrop on those calls without already compromising the server it's running on…

> to my understanding, there's literally no way to eavesdrop on those calls without already compromising the server it's running on That's probably correct (with the caveat that I suspect NSA/FSB/MSS/Mossad/whoever can reasonably be assumed to have backdoored Fortinet) There is still the problem that an attacker with "global passive observer" capabilities (which almost certainly includes most non 3rd world nation sta…

>whoever can reasonably be assumed to have backdoored Fortinet)

Considering the almost weekly discovery of fortinet vulnerabilities that seems like a rather low bar

Re: 0-click deanonymization attack targeting Signal, Discord, other platforms

#463

Earlier quoted context omitted.

A VPN obfuscates this. Assuming a target is even remotely aware, you might think they are in Australia, while they're actually in Nova Scotia

Say I send a message to someone who has a phone with push notifications enabled, showing message previews. Will the phone still be connected to the VPN when it wakes up to display the message? Because my iPhone doesn't seem to stay connected to my VPN when it sleeps, at least not reliably. There really should be a "never use the internet without VPN" mode on devices.

That exists on Android. VPN on ios is known to be rather leaky.

Re: 0-click deanonymization attack targeting Signal, Discord, other platforms

#464

Earlier quoted context omitted.

There's a part of me that's fine with it for a short-lived URL which contains a temporary access key but for a forever URL with a forever access key I'm not entirely happy with it. I use it to share memes and shitpost but definitely not something to share sensitive content IMO.

Discord doesn't do forever URLs for attachments any more, they changed that a while back.[0] The problem here is avatar URLs. [0] https://www.bleepingcomputer.com/news/security/discord-will-...

This is good to know, thanks for sharing this knowledge.

Re: 0-click deanonymization attack targeting Signal, Discord, other platforms

#465

Clever finding but the title does no justice to the actual attack. Even a bare minimum threat model requires a user to use VPN or Tor which completely eliminates your "0day". Signal rightfully declined your report because it's only job is to provide secure communication

Typical mobile user with a VPN is still vulnerable as far as I can tell, because they may be disconnected while displaying a push notification, but feel free to prove me wrong: https://news.ycombinator.com/item?id=42786466

I have no idea about iOS but there have been past reports on it being extremely leaky and how apple basically white lists it's domains to bypass the VPN connection. Android doesn't suspend the VPN connection in any state, that's for sure

Re: 0-click deanonymization attack targeting Signal, Discord, other platforms

#466
post #342

I'm a bit at a loss there. Has _anyone_ ever considered Signal to be anonymous? Or Discord? If so, I have bad news: they are not anonymous. At all. Not even slightly anonymous. Nor did they ever claim to be, they only claim to not be able to read your messages (Signal claims that, I don't know about Discord, I doubt it). And that claim has flaws (sure the crypto is sound but have you thoroughly reviewed and compiled…

People keep forgetting anonymous and private are two different things

Re: 0-click deanonymization attack targeting Signal, Discord, other platforms

#467

Earlier quoted context omitted.

Typical mobile user with a VPN is still vulnerable as far as I can tell, because they may be disconnected while displaying a push notification, but feel free to prove me wrong: https://news.ycombinator.com/item?id=42786466

I have no idea about iOS but there have been past reports on it being extremely leaky and how apple basically white lists it's domains to bypass the VPN connection. Android doesn't suspend the VPN connection in any state, that's for sure

Android seems to disconnect from VPN when sleeping, but I see Android has an "always on" option for VPN that'll block all non-VPN traffic until the VPN reconnects. So users have to make sure that's enabled.

Re: 0-click deanonymization attack targeting Signal, Discord, other platforms

#468
post #440
post #395

Earlier quoted context omitted.

WhatsApp has an option to disable link previews. Surprised signal doesn't have this option. I only message people I know on Signal anyway. Edit: it seems signal does have the option

I had this same thought before reading the article - this isn't about link previews, it's about attachment caching

But previewing can involve automatically loading resources. This "attack" is very similar to CSRF in that your exploit involves making the victim load a specific resource. That's why in secure mail clients, nothing but plaintext should be rendered, and an optional "Load all resources" button is shown for when you trust the sender, and want to load any media elements that require HTTP onto your client.

Signal could mitigate this with something similar, where it didn't load the image file AT ALL, and instead showed a message:

wants you to load an image from https://example.com/foo.png. Load image? > Yes > No

Re: 0-click deanonymization attack targeting Signal, Discord, other platforms

#469
post #231

Earlier quoted context omitted.

I would guess some are just jealous of his age, but some do find the claim of de anonymizing to simply be overblown given it doesn't tell you nearly enough to find anyone except in very niche cases. This "attack" is easily defeated with a VPN or living in any major city.

Interesting you touched on his age. I got extremely curious, why did the OP did such a flex?(assumming they are telling the truth). The first sentence is such a weird brag that it felt suspicious. The report is highly technical and extremely well written. We're either dealing with a pure genious or a fraud. But why would a genious flex? Doesn't make sense.

The flex is probably because they are 15 and a bit immature.

An anecdote - I used to be the lead for an infotainment security program for a well known manufacturer. They would send me to a lot of small security meetups and training. One in specific was a security training event for some HS students, which I would define as gifted. There were roughly 40 of them, from 14 to 17 years old, and they were all extremely impressive in things ranging from reverse engineering applications to assembly code all the way Linux systems stuff.

Something like this would have been easy for them - I mean the basics of this is that the attacker sends a message to a discord/signal user and then sends a request to a Cloudfare server. Not exactly splitting atoms IMO. What I think is special about this 15 year old in question is the epiphany that it might be possible and then giving it a go. This is the true hacker spirit.

Post reply on HN