5 ms·
Europa.eu domain name contacted through Signal Helper
- schleck8 5y agoIf this was a spying attempt they'd surely set up a less suspicious domain instead of a subdomain On a different note, does someone know what this firewall software is called?
- deleted 5y ago[deleted]
- phaer 5y agoI don't know, but if someone would paste a link to such domain in their signal client, would it be this helper which fetches it to render a preview?
- raverbashing 5y agoThat would be the most likely explanation I would think of.
- ComodoHacker 5y agoGenuine Signal app wouldn't fetch link previews from the client, it's a huge leak.
- VMG 5y agogood point, but where would it fetch it from? the only good solution I can think of is Tor
- dogma1138 5y agoPreviews are handled sender side iirc, so still from the client just no inadvertently.
- ComodoHacker 5y agoPreviews from sender side are prone to spoofing though.
- decrypt 5y agoTurns out to be a link preview: https://community.signalusers.org/t/europa-eu-domain-name-contacted-through-signal-helper/38748/7 https://community.signalusers.org/t/europa-eu-domain-name-co...
- mkreis 5y agoPerhaps IP 147.67.37.17 is used for shared hosting and the reverse DNS lookup from the Firewall software returned a misleading domain.
- ojosilva 5y agoThis IP reports back into ns1bru.europa.eu. This looks like it could be the Signal link preview stack: https://hub.packtpub.com/signal-introduces-optional-link-previews-to-enable-users-understand-whats-behind-a-url/ https://hub.packtpub.com/signal-introduces-optional-link-pre...
- newaccount74 5y agoThe IP has no reverse name configured: > nslookup 147.67.37.17 ** server can't find 17.37.67.147.in-addr.arpa: SERVFAIL So I'm not sure where the host name from the firewall software is coming from. I tried and got a certificate that looks like it is from the European Commission > curl -v https://147.67.37.17 ... * Server certificate: * subject: C=BE; ST=Brussels-Capital Region; L=Brussels; O=European Commission; CN=*.ec.europa.eu ... It looks like this is a server from the EC and I consider it unlikely that they are using a shared hosting provider.
- hosteur 5y agoAm I missing something or is this just a link preview? I don’t think there is any reason to spread fear or panic based on what is provided.
- ComodoHacker 5y agoLooks like it is: > I just found that we shared a link pointing to a governmental domain. I cleaned every log today and retrieved the link then sent it back. The domain has been contacted again. So yes it is related to link preview. But I can't believe Signal devs left such a huge data leak channel in their app.
- md_ 5y agoYou can disable this. But just to be clear, the preview is from the sender. I think it’s reasonable to assume that someone sending a link is willing to click the link, no? (There’s also a “privacy-preserving proxy” in the middle, FWIW: https://signal.org/blog/i-link-therefore-i-am/ https://signal.org/blog/i-link-therefore-i-am/.)
- johnchristopher 5y agoIf the preview comes from a proxy why does the helper perform a dns lookup or hit on that domain ? > I think it’s reasonable to assume that someone sending a link is willing to click the link, no? I think it's reasonable in most cases but my assumption was that Signal was doing the clicking for me discreetly from their servers but reading their blog post now I think I understand it's only for some domains.
- md_ 5y agoGood question. Without looking into it, one theory I might have is that the client does the DNS resolution and then just proxies the HTTP request through Signal's servers. In general, I find the privacy implications of either solution a bit hard to reason about. Having Signal proxy the requests leaks to the website that someone is sending a link to the site via Signal, but not who is sending the link. If the link itself is sufficiently unique, though, that could be an issue. On the other hand, if someone sends me a link and I in turn send it on (without clicking) via Signal, and doing so causes my client IP to be revealed, that seems sorta bad. So the proxy makes sense here. /shrug I don't think any of the risks here are huge, and the options all have tradeoffs, which I guess is why you can disable the feature.
- codefeenix 5y agoATTEMPT NO LANDING THERE.
- johnchristopher 5y ago> I just found that we shared a link pointing to a governmental domain. I cleaned every log today and retrieved the link then sent it back. The domain has been contacted again. So yes it is related to link preview. > Thanks Stefan From a 3 days old account.
- deleted 5y ago[deleted]
- md_ 5y agoNot surprisingly, this turns out to have a totally benign explanation. Still, I do think this demonstrates how hard it is for (apparently) well-meaning, somewhat-technical users to understand what their software does. I don’t think reading over firewall logs is a very good way to ensure trust in client-side software, of course. (Aside from just being ridiculously time-consuming, there are too many easy ways to exfiltrate data. Like…sending it to the Signal servers?) But I do sort of idly wonder, given the ever-increasing complexity of the trusted computing base, how we can make it so users who are (apparently) concerned enough to read over firewall logs can more productively evaluate trust.