Live data from Hacker News

0-click deanonymization attack targeting Signal, Discord, other platforms

gist.github.com

81–90 of 474 posts

Re: 0-click deanonymization attack targeting Signal, Discord, other platforms

#81
post #46

Earlier quoted context omitted.

I guess it can be useful for tracking fugitive political dissidents, terrorists, etc. If you can narrow their location down to 250 miles, it's already very useful information. And without raising any suspicions.

It's not really narrowing it down to 250 miles; its narrowing it down to a circle whose radius is at least 250 miles or ~196,000mi^2. My closest Cloudflare CDN is just listed as "DFW". The DFW metro area is about 8,700mi^2, and I imagine I could be even further than the "metro area" and still get the "DFW" Cloudflare datacenter. In their little video animation, the area inside the overlap of those two circles encompa…

I think it's still useful. Going from "we don't know where Osama bin Laden is at all" to "he's somewhere in Pakistan".

Re: 0-click deanonymization attack targeting Signal, Discord, other platforms

#84

So if you send a picture to a Signal user, it's retrieved via cloudflare, and cached in a data center near that user; now you can look up the cache status and find the data center used. I'd say "deanonymization" is stretching it, unless the user is in the middle of nowhere (no other users near the data center). But interesting writeup anyway.

Send picture to multiple accounts, perhaps on different services, the links that are cached at the same data center can be more confidently believed to be related.

Re: 0-click deanonymization attack targeting Signal, Discord, other platforms

#85

For being 15 year old, cool work! But calling this de-anonymization is a stretch, if it can possibly pinpoint you within 250 miles (that's assuming geoip is correct too, which it rarely is). In their GeoGuesser demonstration video, the higlighted area is densely populated and you still would need to match millions of people vs the online user. It does provide some hints as to the location of the targeted user, and th…

It is already more than enough to know which country to contact the authorities and to pinpoint a rough area where to look.

If the scammer is in Nigeria, tough luck. If he is in the EU or US then exists a feasible chance to go after the person.

Re: 0-click deanonymization attack targeting Signal, Discord, other platforms

#86
post #81

Earlier quoted context omitted.

It's not really narrowing it down to 250 miles; its narrowing it down to a circle whose radius is at least 250 miles or ~196,000mi^2. My closest Cloudflare CDN is just listed as "DFW". The DFW metro area is about 8,700mi^2, and I imagine I could be even further than the "metro area" and still get the "DFW" Cloudflare datacenter. In their little video animation, the area inside the overlap of those two circles encompa…

I think it's still useful. Going from "we don't know where Osama bin Laden is at all" to "he's somewhere in Pakistan".

If only we knew OBL's Discord handle then we would have known he was about where we figured he was all along...

And then this whole thing gets thrown off if one uses a VPN with an endpoint somewhere other than where you are. Click a button, suddenly my datacenter is AMS. Click it again, suddenly its OTP...

Re: 0-click deanonymization attack targeting Signal, Discord, other platforms

#87

Am I correct in surmising that someone who uses aVPN on their phone, while sending Signal messages/ content, would be cloaked, provided the VPN server they pick isn't near them ?

Yes, that is correct. VPN near location would be disclosed, not yours.

Re: 0-click deanonymization attack targeting Signal, Discord, other platforms

#88
post #51

Earlier quoted context omitted.

> Don’t get me wrong the write up is really interesting but it does feel like the author is a bit of a sensationalist. They claim to be 15 years old. Cut them some slack.

"bit of a sensationalist" is reasonable feedback; no slack needed. After all, this is how they learn.

people learn when they’re given kind, direct, actionable feedback from people they trust - not when they’re called sensationalists by random critics on the internet.

what have you made lately?

Re: 0-click deanonymization attack targeting Signal, Discord, other platforms

#89
post #59
post #15

Earlier quoted context omitted.

depending on the circumstance, the rough area might already be useful to adversaries of the person trying to hide. I wouldn't expect things like criminals etc. to suffer from this, 300 miles is a big radius for example... but if you want to know if 'the guy is still in country' or something like that (for instance law enforcement) it's useful for them. such parties could then collaborate with local resources to do fu…

Law enforcement could probably just ask cloudflare for the exact IP address that retrieved the attachment.

Only if they're from a friendly country. If the reason a user needs anonymity is geopolitical, that isn't a guarantee.

Re: 0-click deanonymization attack targeting Signal, Discord, other platforms

#90
post #12

"Signal instantly dismissed my report" "Telegram, another privacy-focused application, is completely invulnerable to this attack" "Discord […] citing this as a Cloudflare issue other consumers are also vulnerable to" "Cloudflare ended up completing patching the bug" I wish Signal would react differently. I still remember the bubble color controversy when they changed their mind after the backlash and not before. :-)

[flagged]
Post reply on HN