Earlier quoted context omitted.
I guess it can be useful for tracking fugitive political dissidents, terrorists, etc. If you can narrow their location down to 250 miles, it's already very useful information. And without raising any suspicions.
It's not really narrowing it down to 250 miles; its narrowing it down to a circle whose radius is at least 250 miles or ~196,000mi^2. My closest Cloudflare CDN is just listed as "DFW". The DFW metro area is about 8,700mi^2, and I imagine I could be even further than the "metro area" and still get the "DFW" Cloudflare datacenter. In their little video animation, the area inside the overlap of those two circles encompa…
0-click deanonymization attack targeting Signal, Discord, other platforms
81–90 of 474 posts
Re: 0-click deanonymization attack targeting Signal, Discord, other platforms
#82What's old is new. Does anyone remember the forum signatures that would display the viewers IP address and location on a little wooden signpost held up by a troll-looking creature? https://cdn.geekzone.co.nz/images/forums/danasoftcache.jpg
Re: 0-click deanonymization attack targeting Signal, Discord, other platforms
#83[flagged]
Re: 0-click deanonymization attack targeting Signal, Discord, other platforms
#84So if you send a picture to a Signal user, it's retrieved via cloudflare, and cached in a data center near that user; now you can look up the cache status and find the data center used. I'd say "deanonymization" is stretching it, unless the user is in the middle of nowhere (no other users near the data center). But interesting writeup anyway.
Re: 0-click deanonymization attack targeting Signal, Discord, other platforms
#85For being 15 year old, cool work! But calling this de-anonymization is a stretch, if it can possibly pinpoint you within 250 miles (that's assuming geoip is correct too, which it rarely is). In their GeoGuesser demonstration video, the higlighted area is densely populated and you still would need to match millions of people vs the online user. It does provide some hints as to the location of the targeted user, and th…
If the scammer is in Nigeria, tough luck. If he is in the EU or US then exists a feasible chance to go after the person.
Re: 0-click deanonymization attack targeting Signal, Discord, other platforms
#86Earlier quoted context omitted.
It's not really narrowing it down to 250 miles; its narrowing it down to a circle whose radius is at least 250 miles or ~196,000mi^2. My closest Cloudflare CDN is just listed as "DFW". The DFW metro area is about 8,700mi^2, and I imagine I could be even further than the "metro area" and still get the "DFW" Cloudflare datacenter. In their little video animation, the area inside the overlap of those two circles encompa…
I think it's still useful. Going from "we don't know where Osama bin Laden is at all" to "he's somewhere in Pakistan".
And then this whole thing gets thrown off if one uses a VPN with an endpoint somewhere other than where you are. Click a button, suddenly my datacenter is AMS. Click it again, suddenly its OTP...
Re: 0-click deanonymization attack targeting Signal, Discord, other platforms
#87Am I correct in surmising that someone who uses aVPN on their phone, while sending Signal messages/ content, would be cloaked, provided the VPN server they pick isn't near them ?
Re: 0-click deanonymization attack targeting Signal, Discord, other platforms
#88Earlier quoted context omitted.
> Don’t get me wrong the write up is really interesting but it does feel like the author is a bit of a sensationalist. They claim to be 15 years old. Cut them some slack.
"bit of a sensationalist" is reasonable feedback; no slack needed. After all, this is how they learn.
what have you made lately?
Re: 0-click deanonymization attack targeting Signal, Discord, other platforms
#89Earlier quoted context omitted.
depending on the circumstance, the rough area might already be useful to adversaries of the person trying to hide. I wouldn't expect things like criminals etc. to suffer from this, 300 miles is a big radius for example... but if you want to know if 'the guy is still in country' or something like that (for instance law enforcement) it's useful for them. such parties could then collaborate with local resources to do fu…
Law enforcement could probably just ask cloudflare for the exact IP address that retrieved the attachment.
Re: 0-click deanonymization attack targeting Signal, Discord, other platforms
#90"Signal instantly dismissed my report" "Telegram, another privacy-focused application, is completely invulnerable to this attack" "Discord […] citing this as a Cloudflare issue other consumers are also vulnerable to" "Cloudflare ended up completing patching the bug" I wish Signal would react differently. I still remember the bubble color controversy when they changed their mind after the backlash and not before. :-)