Live data from Hacker News

0-click deanonymization attack targeting Signal, Discord, other platforms

gist.github.com

71–80 of 474 posts

Re: 0-click deanonymization attack targeting Signal, Discord, other platforms

#71
post #40

Earlier quoted context omitted.

Last time I used Cloudflare I think their settings default to only "Origin SSL/TLS" (or whatever they call it), which wouldn't encrypt anything between Cloudflare and the origin, it would only encrypt data between Cloudflare and the end-user/browser.

TLS doesn’t matter for End-to-end encrypted stuff though, you could exchange the data over Telnet and it would still be secure. The content itself is already encrypted before being transmitted and can only be decrypted by the receiver.

AFAIK the attack described by OP only works if the attacker knows the (randomly generated) URL of the image, which probably means they have a Signal client that can decrypt the image already. So the secrecy of the content is not at issue. The question is whether some specific person has received the same image, and from where.

Re: 0-click deanonymization attack targeting Signal, Discord, other platforms

#72

Earlier quoted context omitted.

Step 2: If you use Discord, don't allow invites from _anyone_. Its quite bizarre why social media apps allow anonymous people to interact with you. 99% of the conversation I have is with people that I roughly know.

So, how would you start interacting with your friends if you just created account? >anonymous people Wtf, how is this even relevant?

You can add them by creating a unique, temporary UUIDs/links that they can use?

You know them from somewhere else, lets say I play a game and we decided to get into a voice chat. We could create a temporary, dynamically created voice chat that we can all join (much like Google Meet) where all of us are anons.

Then, if we really want to know each other, we can then share the UUIDs.

I understand why ANYONE can send an email to me (I can decide when/will to check them)

I don't understand why ANYONE can whisper to my ears (I cant decide since they are pushed to the top of the app)

Re: 0-click deanonymization attack targeting Signal, Discord, other platforms

#73
post #26

Earlier quoted context omitted.

Step 2: If you use Discord, don't allow invites from _anyone_. Its quite bizarre why social media apps allow anonymous people to interact with you. 99% of the conversation I have is with people that I roughly know.

Discord is for gamers and quite a lot of people will be playing a game and tell someone "add me on discord my tag is xyz". Not allowing invites would seriously cut into the usability.

You could have it so both people have to add each other before there's any indication that either person added the other.

No extra work for person A, and the work for person B is just what person A had to do anyway.

Re: 0-click deanonymization attack targeting Signal, Discord, other platforms

#74

Cool writeup with some interesting techniques and approaches! I'll echo the other comments and say "deanonymization" is stretching the definition of the word, along with "grab the user's location", as it isn't anything near precise. 150 miles is approx. a 2-hour drive on the highway from Atlanta, GA to Augusta, GA. In that radius, there's probably 700,000+ people. I do think the auto-retrieve attachment feature of Si…

> "deanonymization" is stretching the definition of the word, along with "grab the user's location", as it isn't anything near precise.

You'd think so, but you would be surprised how quickly this adds up to other details people share, like "oh I just drove 15 minutes to get Starbucks" or something to that effect, small things that eventually add up to a precise location over time.

Re: 0-click deanonymization attack targeting Signal, Discord, other platforms

#75
post #34
post #15

Earlier quoted context omitted.

depending on the circumstance, the rough area might already be useful to adversaries of the person trying to hide. I wouldn't expect things like criminals etc. to suffer from this, 300 miles is a big radius for example... but if you want to know if 'the guy is still in country' or something like that (for instance law enforcement) it's useful for them. such parties could then collaborate with local resources to do fu…

You would know if they are over a cellular network or checking on mobile. If someone sends you a youtube link and you hit play, YT knows who you are, both from a network perspective and potentially the logged in user. If you are using signal in a high risk environment, you should be using it from a system that contains no extra information about you. This is the same posture one should take when using Tor. Basic opse…

i don't think you can call opsec basic, since it requires tons of knowledge about technology and techniques adversaries might deploy against you. targets of attacks don't neccesarily have this kind of knowledge.

opsec is _incredibly_ hard for a person not deeply into technology and this type of information. you might argue that you need to stick with certain tools and techniques that are known good, but new vulnerabilities and techniques implemented against you can completely shatter previous knowledge on whats good and bad opsec and still break it despite doing it 'very well'. (like certain darknet markets being closed down due to new vulnerabilities being found in the platforms they use...)

most people who rely on opsec/tradecraft for a living, also rely on teams of people to help them maintain it and validate it constantly... (or eventually fail and get bitten).

you are right though that its unlikely a company or app producer would have a threat model tuned to people who want to hide stuff. those things generally tend to be closed down sooner or later. (encrochat and such services...)

Re: 0-click deanonymization attack targeting Signal, Discord, other platforms

#76
post #31

What's old is new. Does anyone remember the forum signatures that would display the viewers IP address and location on a little wooden signpost held up by a troll-looking creature? https://cdn.geekzone.co.nz/images/forums/danasoftcache.jpg

Had a friend who made his own nice one, would then visit the thread, and figure out "who is viewing it" and show your username. ;)

Re: 0-click deanonymization attack targeting Signal, Discord, other platforms

#77
post #59
post #15

Earlier quoted context omitted.

depending on the circumstance, the rough area might already be useful to adversaries of the person trying to hide. I wouldn't expect things like criminals etc. to suffer from this, 300 miles is a big radius for example... but if you want to know if 'the guy is still in country' or something like that (for instance law enforcement) it's useful for them. such parties could then collaborate with local resources to do fu…

Law enforcement could probably just ask cloudflare for the exact IP address that retrieved the attachment.

do you think law enforcement in Iran will get an answer from cloudflare?

Re: 0-click deanonymization attack targeting Signal, Discord, other platforms

#78
post #31

What's old is new. Does anyone remember the forum signatures that would display the viewers IP address and location on a little wooden signpost held up by a troll-looking creature? https://cdn.geekzone.co.nz/images/forums/danasoftcache.jpg

That was a troll feature. It usually showed any user his own information. MAYBE some forum doxxed users by posting their informatio? but I didn't see any.

My friend would figure out the username, but he never did it maliciously, just for the challenge. Forums would show you which user was viewing a thread...

Re: 0-click deanonymization attack targeting Signal, Discord, other platforms

#79

So if you send a picture to a Signal user, it's retrieved via cloudflare, and cached in a data center near that user; now you can look up the cache status and find the data center used. I'd say "deanonymization" is stretching it, unless the user is in the middle of nowhere (no other users near the data center). But interesting writeup anyway.

"Near a user" is also a big assumption. I'm ~200 miles to ORD and ~500 to IAD, but my ISP's peering & upstream arrangements mean Cloudflare serves my traffic 700 miles from DFW. But, at the same time: Cloudflare isn't going to serve me a cache from Seattle, Manchester, or Tokyo. Pinning down an unknown Signal user to even a rough geographic location is an important bit of metadata that could combine to unmask an indi…

[deleted]

Re: 0-click deanonymization attack targeting Signal, Discord, other platforms

#80
post #46

Unless I'm missing something, this seems like an incredibly long winded way to check the users IP location? For example, connecting to a VPN and checking https://cloudflare.com/cdn-cgi/trace gives me `colo:CPH` (Copenhagen) which is far from my nearest CF datacenter (geographically), closer to the IP location from my VPN provider (Oslo) but still not particularly close? If I don't use a VPN, I don't even get the capi…

I guess it can be useful for tracking fugitive political dissidents, terrorists, etc. If you can narrow their location down to 250 miles, it's already very useful information. And without raising any suspicions.

It's not really narrowing it down to 250 miles; its narrowing it down to a circle whose radius is at least 250 miles or ~196,000mi^2.

My closest Cloudflare CDN is just listed as "DFW". The DFW metro area is about 8,700mi^2, and I imagine I could be even further than the "metro area" and still get the "DFW" Cloudflare datacenter.

In their little video animation, the area inside the overlap of those two circles encompasses several states. The edges of the two circles go from Washington to Florida and almost include Chicago. The target could have been in Denver or St Louis or Las Vegas or Phoenix or San Diego or San Francisco or Amarillo or El Paso.

Post reply on HN