Wouldn't other user that sees the other person's profile picture also drum up the cache? This wouldn't work for someone in a large server.
0-click deanonymization attack targeting Signal, Discord, other platforms
91–100 of 474 posts
Re: 0-click deanonymization attack targeting Signal, Discord, other platforms
#92I don't know about the UD bit this will not be very accurate within the EU.
As an example: In Hungary, there's pretty much only one peering hub (bix) and there's only one Cloudflare datacenter. You've already geolocated me better than this hack just by knowing my language or phone prefix.
Re: 0-click deanonymization attack targeting Signal, Discord, other platforms
#93Cool writeup with some interesting techniques and approaches! I'll echo the other comments and say "deanonymization" is stretching the definition of the word, along with "grab the user's location", as it isn't anything near precise. 150 miles is approx. a 2-hour drive on the highway from Atlanta, GA to Augusta, GA. In that radius, there's probably 700,000+ people. I do think the auto-retrieve attachment feature of Si…
> "deanonymization" is stretching the definition of the word, along with "grab the user's location", as it isn't anything near precise. You'd think so, but you would be surprised how quickly this adds up to other details people share, like "oh I just drove 15 minutes to get Starbucks" or something to that effect, small things that eventually add up to a precise location over time.
Yes, but if social engineering is involved and tracing back through user conversations across a platform, it's hardly a vulnerability, let alone one deserving of a bounty. The way this is currently functioning is intended functionality, and can be further locked down depending on the user's threat model.
This can essentially be classified as opsec failure for the Signal user. If they're trying to hide from a hit in a 300 mile radius, they've got bigger problems to worry about, and should already be using a VPN setup.
Every time you click on a link your external IP addresses is exposed, is this a vulnerability? Being online without a VPN / proxy is inherent consent to have your external IP & other required items to be shared with services / middlemen.
When it comes to Discord, if you have this strict of a threat model and you're still using it, idk what to tell you.
Re: 0-click deanonymization attack targeting Signal, Discord, other platforms
#94Earlier quoted context omitted.
Their twitter says > Joined November 2017 so likely a bit older :)
Ah, that's true. They even have HackerOne activity from 8 years ago: https://hackerone.com/daniel/hacktivity?type=user So either they lied about their age then in order to join social media and they're some sort of child prodigy... or they're lying now.
Re: 0-click deanonymization attack targeting Signal, Discord, other platforms
#95So if you send a picture to a Signal user, it's retrieved via cloudflare, and cached in a data center near that user; now you can look up the cache status and find the data center used. I'd say "deanonymization" is stretching it, unless the user is in the middle of nowhere (no other users near the data center). But interesting writeup anyway.
It gets more interesting when you think about the impact on groups. Sending an image to a group is enough for all devices associated with that group to be identifiable from CloudFlare's side, who additionally see a giant chunk of unencrypted traffic from the same client addresses going to other web sites. Given Cloudflare's less-than-straight approach to sales, it is astonishing the words "secure" and "Signal" ever a…
Doesn't this open up the possibility to identify groups that have been infiltrated by spies or similar posers? If you use this method to kinda-sorta locate or identify all the users in your group and one or more of those users ends up being located in a region where you should have no active group members then you may have identified a mole in your network.
Just thinking out loud here since there's no one else home.
Re: 0-click deanonymization attack targeting Signal, Discord, other platforms
#96Earlier quoted context omitted.
I think it's still useful. Going from "we don't know where Osama bin Laden is at all" to "he's somewhere in Pakistan".
If only we knew OBL's Discord handle then we would have known he was about where we figured he was all along... And then this whole thing gets thrown off if one uses a VPN with an endpoint somewhere other than where you are. Click a button, suddenly my datacenter is AMS. Click it again, suddenly its OTP...
Discord is just an example, this can apparently work with many apps that store user attachments on Cloudflare.
>Click a button, suddenly my datacenter is AMS. Click it again, suddenly its OTP...
Well, if the location keeps changing, it's obvious it's not their real location. But if it’s always the same, no matter what, that’s a huge clue. Of course, this works best when you’ve got some other data to back it up. It’s kind of like playing Akinator - the more answers you get, the closer you get to figuring out the target. One answer might not tell you much, but three or four?
Re: 0-click deanonymization attack targeting Signal, Discord, other platforms
#97"Signal instantly dismissed my report" "Telegram, another privacy-focused application, is completely invulnerable to this attack" "Discord […] citing this as a Cloudflare issue other consumers are also vulnerable to" "Cloudflare ended up completing patching the bug" I wish Signal would react differently. I still remember the bubble color controversy when they changed their mind after the backlash and not before. :-)
I understand that Signal does not consider this
https://gist.github.com/hackermondev/45a3cdfa52246f1d1201c1e8cdef6117 to be
a valid security bug, but it would be helpful to at least be able to
mitigate it.
Please add an option in settings to disable automatically downloading
attachments.
That should be enough to change the attack from 0-click (just opening the
conversation) to 1-click (click the attachment). Most people won’t care
about this, but for some every little bit of privacy is important.
[1]: https://support.signal.org/hc/en-us/requests/newRe: 0-click deanonymization attack targeting Signal, Discord, other platforms
#98Earlier quoted context omitted.
If only we knew OBL's Discord handle then we would have known he was about where we figured he was all along... And then this whole thing gets thrown off if one uses a VPN with an endpoint somewhere other than where you are. Click a button, suddenly my datacenter is AMS. Click it again, suddenly its OTP...
>If only we knew OBL's Discord handle then we would have known he was about where we figured he was all along... Discord is just an example, this can apparently work with many apps that store user attachments on Cloudflare. >Click a button, suddenly my datacenter is AMS. Click it again, suddenly its OTP... Well, if the location keeps changing, it's obvious it's not their real location. But if it’s always the same, no…
Re: 0-click deanonymization attack targeting Signal, Discord, other platforms
#99Re: 0-click deanonymization attack targeting Signal, Discord, other platforms
#100"Signal instantly dismissed my report" "Telegram, another privacy-focused application, is completely invulnerable to this attack" "Discord […] citing this as a Cloudflare issue other consumers are also vulnerable to" "Cloudflare ended up completing patching the bug" I wish Signal would react differently. I still remember the bubble color controversy when they changed their mind after the backlash and not before. :-)
[flagged]