7 ms·
Abusing WebRTC to reveal coarse location data in Signal
- verdverm 6y agoI recall seeing a paper where they showed how close you can geolocate with various numbers of peers to the target, by using network latency alone
- ravenstine 6y agoThat's pretty interesting. So, effectively, a triangulation based on latency times?
- Avamander 6y ago> So, effectively, a triangulation based on latency times? Yes.
- Disposition 6y agoHate to be a pedant, but it's technically trilateration.
- stagas 6y agoI didn't know this term, thank you for being such a pedant :) knowing the right term makes it easier to find information on the subject.
- stagas 6y agoThat's funny, I was just working on a POC like this today[0] - it's accurate most of the time for my location but I haven't tested from other locations. You'd need to tweak the 'known' servers on and off to find the optimal arrangement because you'd need to be somehow inside the polygon. I was planning to find a way to discover these itself and other tweaks (like trying multiple times then averaging out) Edit: the paper I found related to this is here[1] [0]: https://github.com/stagas/http-geolocate https://github.com/stagas/http-geolocate [1]: https://homes.cs.washington.edu/~tom/support/geoloc.pdf https://homes.cs.washington.edu/~tom/support/geoloc.pdf
- RL_Quine 6y agohttps://vercel.com/edge-network https://vercel.com/edge-network This page contains websocket addresses of a CDN that returns ping pong from a huge number of locations. It works surprisingly well for working out very fine grain location in just playing with it.
- stagas 6y agoOh wow, they're actually doing the same thing, triangulating on latency. Hive mind, I guess. I used universities because I figured a)they won't mind, and b)they're more likely to have their servers on premises, then used a public reverse geoip to get their locations. I'll try to see if I can integrate with Vercel's edge network, seems more ideal. Edit: no, I misunderstood, the location dot that's being displayed isn't the product of triangulation, they're just doing reverse geoip lookup. So, I wonder now if the edge network would perform better. Update: it doesn't perform better. Either there is some kind of proxy redirecting their traffic or these servers aren't where they say they are, the center is skewed out completely. The universities win so far being correct and accurate most of the time.
- LargoLasskhyfv 6y agoUnimpressed with yours. Why? Because my ISP got some IPv4 space recently, which was formerly allocated to .ua, .ru, .iq, & .ir. While being physically next to or in Hamburg, .de. That led to all sorts of inconveniences for some people, suddenly barred from logging on, or using the sites they frequent, because they used outdated geo-ip data. I didn't even notice, except for the outrage in their customer forum. Now yours consistently puts me somewhere into, or onto the shores of the Black Sea, while Vercels doesn't. So that makes me suspicious of your claim by using latency alone. Edit: There seems to be outdated geo-ip information factored in somewhere. Why else it would put me IN the Black Sea?
- stagas 6y agoI mentioned I just started working on it. To try for yourself you'd need to clone and tweak the servers list to find an optimal arrangement for you. The problem as I see it is that jumping continents occurs really artificial delays which skews the result significantly, so it first needs to identify your relative whereabouts, then decide on an optimal set of servers. If you clone and tweak the servers to place yourself inside the polygon you'd see it does locate you. Vercel is doing a reverse geoip lookup, so your location is preconfigured in some database based on your ip.
- cjbprime 6y agoWould be interesting to see a link! That doesn't sound like it would get an accurate guess to me, given facts like "light travels slower in copper than fiber" and "your packets have to enter a country through specific large hubs" etc etc.
- Avamander 6y agoIf you have enough machines you can just use machines after those large hubs. The copper/glass light speed difference doesn't matter much because the speed differences added by hops in the middle are usually orders of magnitudes higher. In the end, unless you've got machines next door pinging your target you won't be able to differentiate between houses or city blocks.
- kodablah 6y agoI can see where a FQDN candidate is no biggie in a browser's offer/answer since DNS lookups occur all the time. But I imagine the simple fix for Signal's WebRTC use, since they control both sides of the exchange, is to just disregard non-IP candidates. Or even better, don't do anything with the candidates until the call is accepted. Worst case, could just have a geographically centralized signaling server (or shared IP). Granted, since Signal controls both sides, might as well only serve fixed "host" candidates and disallow any offer/answer with custom crafted ones. One also wonders, to prevent other forms of leaks, if Signal can make a blanket policy to prevent DNS lookups or in general get tighter control on outbound network.
- pthatcherg 6y agoDisregarding non-IP candidates is exactly what we've chosen to do (and which the new versions of the app do). The downside of disregarding all candidates until the call is accepted is that post-accept connectivity would be much slower. Going through a server to hide your IP is an option in the settings in the app, but it can potentially lead to higher call latency, so there is a trade-off. To prevent issues like this in the future we are taking more control of WebRTC's behavior with a fork of WebRTC (Signal uses WebRTC) and are providing patches to upstream WebRTC as well. (I work at Signal on calling)
- billme 6y ago>> “ PINs will also help facilitate new features like addressing that isn’t based exclusively on phone numbers, since the system address book will no longer be a viable way to maintain your network of contacts.” [1] Any idea when more information might be available on this? Asked moxie years ago to add this and know 100s of other have too. Worth noting the FAQ as it relates to the PIN length is not correct, “How long can my PIN be? There is no limit. Feel free to add as many characters as you want.” [2] ...tested it and longest PIN I was able to create was 20 characters all numeric. [1]: https://signal.org/blog/signal-pins/ https://signal.org/blog/signal-pins/ [2] https://support.signal.org/hc/en-us/articles/360007059792-Signal-PINs https://support.signal.org/hc/en-us/articles/360007059792-Si...
- upofadown 6y ago>Even Edward Snowden, the well known American Whistleblower, claims “I use Signal every day.” Well, 5 years ago...
- mike_d 6y agoEdward Snowden has a vastly different risk profile than anyone else. It it without a doubt that he is under constant electronic and physical surveillance by the Russian and American governments. His phones and computers are also very likely compromised. At that point your choice of messenger app matters about as much as the color of your socks because the interception is happening at another layer.
- cjbprime 6y agoPresumably he's been using Signal over Tor, defeating all such attacks as a side-effect.
- aesh2Xa1 6y agoHow does Edward Snowden acquire a laptop or phone in a way that he can trust it? I don't think it matters what protocols and applications he uses: he does not enjoy privacy.
- thephyber 6y agos/Edward Snowden/anyone/ Two key words in your comment are both spectrums: trust and privacy. Most people implicitly trust their hardware more than Snowden does now -- they overestimate the security from the factory and he probably has better expectations of the likelihood of hardware compromise. On the privacy spectrum, one point is how much privacy you think you have, and the other (unknown) point is how much you actually have. Similarly, I think Snowden's situation and prior experience helps him more accurately understand where those points are; the rest of us are up on the first peak of the Dunning-Kreuger chart.
- sadfklsjlkjwt 6y agoI order to get a device that is not explicitly compromised with custom targeted malware one could: take a walk, enter a random shop, buy a device. Now you only have the standard malware that everyone gets preinstalled on their devices. How to keep it free of custom targeted malware? That is another question!
- DrPhish 6y agoThe only universal fix I can think of for this class of attacks is to have routers bound latency to a lower limit (eg. 200ms), with fixed latency buckets (eg. 500ms granularity) when it goes beyond that. That is, no traffic would traverse the router in less than 200ms, and every other flow would be fixed at 700ms, 1200ms, 1700ms, etc amounts of latency. Tweaked correctly that would limit location to continent, unless I'm missing something. It would effectively trade quick responses to/from close networks for some extra amount of privacy (in the case that GeoIP has already been taken care of) The latency would have to be controlled on both ingress and egress to account for internal and external threats. I've got a niggling feeling that an attacker that could control latency of enough geographically diverse networks could find the boundary by manipulating responses to get finer detail, but can't quite work the problem into a solution... Is there a less horrible or more reliable universal mitigation that I'm not thinking of?
- andrewstuart2 6y agoI find that interesting, because you could probably classify physical location revelation attacks with other timing-based attacks for which we've had to resort to constant-time algorithms (e.g. key protection via constant-time cryptographic operations). There's an interesting fundamental tradeoff somewhere between optimization and information. If you make things as efficient as possible, you'll probably leak information.
- jerrysievert 6y ago> If you make things as efficient as possible, you'll probably leak information. at which point the threshold could lower ...
- skybrian 6y agoOne problem might be with latencies right at the boundary between two buckets. A bit of jitter would let you know you're near the edge with enough sampling. And if you can add a little latency then you can move the boundary where you like. It seems like the only way to avoid that is with one bucket (constant time).
- sneak 6y agohttps://archive.is/SYq8H https://archive.is/SYq8H I got a blank page on the original domain, perhaps due to DNS adblocking.
- controlweather 6y agoI was once fired from a telecom company in SF for finding that webrtc twilio packets all went through China who was taking a copy and routing back. I investigated because customers complained of heavy delays in their voip. So yeah that was like 7 years ago.
- extropy 6y agoYou already have the peers IP address for p2p call right? How is this better than that?
- meowface 6y agoAccording to the article, by default Signal will relay all calls from people who aren't contacts. This means if a non-contact calls you or vice versa, they can't see your IP address and you can't see theirs, even if the call is accepted and you're both talking. They also provide an option to enable relaying calls to/from contacts, so that contacts won't see your IP address, either. Here, regardless of if you have that setting enabled or not, and regardless of if you accept the call, contacts and non-contacts can cause your device to make a DNS request, which will leak your DNS server. And if using a DNS server with EDNS Client Subnets, the first 3 octets of your IP address will also be leaked. I think there's another issue like what you're describing which can kind of obviate this, though: the vast majority of Signal users probably use Signal on their regular mobile phone and its number, not a burner phone/SIM/number. (Few users probably even own a burner phone/SIM/number or understand what that is or why they might want one or how they'd obtain one.) So... everyone can just see your phone number, which probably has an area code corresponding to your city or close to it, and the other digits can possibly pinpoint it even more precisely than that. Anyone who isn't tunneling all of their DNS traffic with a VPN or otherwise probably also isn't anonymizing their phone number and just has the app installed on their personal, standard cell phone. If they aren't traveling and haven't moved recently, you can probably see what city they're in just from that. (This exposure does allow coarse location detection even when someone's traveling, though it's a lot more coarse than the area code, unless the Client Subnet value is being sent.)
- dep_b 6y agoWebRTC and signaling can be an interesting attack vector. If rooms are not protected technically from uninvited people to enter you can get all kinds of information but even worse you can sometimes even hijack a call.
- floatboth 6y ago> if a Signal user wishes to hide their private/public IP addresses even from contacts who call, then it has an option “Always Relay Calls” in its privacy options I thought Signal was all about privacy by default? :D Signal fans love to dunk on Telegram for secret chats not being the only kind of chat.. well turns out on Signal, private is not the only kind of call, and your IP address is exposed by default.
- vinay427 6y agoI'm unclear why you claim that "private is not the only kind of call." [EDIT below to clarify.] Also, your IP address is only potentially revealed to your contacts, which is rather different from the Telegram situation in which another party that you don't specifically authorize has access to your data. EDIT: What I meant by this, as upon re-reading it seems unclear, is that the privacy as I understand it is not supposed to protect one party from the other party with which they are communicating, but rather conceal the conversation from third parties.
- lxgr 6y agoThe confusion seems to stem from two kinds of privacy goals here: Metadata privacy towards third parties (i.e. who is calling who; Signal explicitly does not provide this) and reciprocal location privacy of two calling parties (i.e. I don't know where I am called from and vice versa, only who I am talking to). Signal's conscious choice is to interpret a user adding another as a contact as an implicit signal to mark them trustworthy enough to forfeit the second kind of privacy in exchange for better voice quality (latency and bandwidth) as well as to lighten the strain on their resources.
- emerongi 6y agoI thought Signal is more about privacy for the masses. Signal claims the call quality is better when this option is not enabled, so it makes sense to leave it off if your goal is to actually have users use your app. The call itself is still encrypted.
- lxgr 6y agoTelegram has the exact same default (allow P2P calls for contacts only). In my opinion, this is a reasonable default: Relaying all voice calls would use significant resources and might increase latency for users far away from the nearest relay (topologically or geographically). Also, what's with the snarkiness? Are Signal's security tradeoffs or vulnerabilities somehow making Telegram more or less secure? The two of them intentionally make different security/usability tradeoffs (the most significant one being Telegram's choice to provide a server-side message history visible to the service operator). Of course this tradeoff isn't inherently bad, but weird communication and branding on Telegram's side in the past has given this a weird aftertaste that, at least for me, is still sticking around.