49 ms·
0-click deanonymization attack targeting Signal, Discord, other platforms
- cedws 2y agoUnfortunate that Cloudflare patched the issue enabling specific datacenters to be targeted. Would have been extremely useful for finding the location of servers behind Cloudflare.
- knowitnone 2y agoI'm sure this is nice to find what city/country someone is but not what I consider "incredibly precise"
- internet_points 2y agoSo if you send a picture to a Signal user, it's retrieved via cloudflare, and cached in a data center near that user; now you can look up the cache status and find the data center used. I'd say "deanonymization" is stretching it, unless the user is in the middle of nowhere (no other users near the data center). But interesting writeup anyway.
- wkat4242 2y ago> (no other users near the data center). Yeah and in that case there won't be a data center because who puts one in places without clients nearby? :)
- naavis 2y agoIndeed, "incredibly precise estimate of the user's location" feels like an exaggeration. But still, very interesting!
- bigbones 2y agoIt gets more interesting when you think about the impact on groups. Sending an image to a group is enough for all devices associated with that group to be identifiable from CloudFlare's side, who additionally see a giant chunk of unencrypted traffic from the same client addresses going to other web sites. Given Cloudflare's less-than-straight approach to sales, it is astonishing the words "secure" and "Signal" ever appear in the same sentence. CloudFlare get to see a fuckton of metadata from private and group chats, enough to trace who originally sends a piece of media (identifiable from its file size), who reads it, when it is is read, who forwards it and to whom. It really doesn't matter that they can't see an image or video, knowing its size upfront or later (for example in response to a law enforcement request) is enough
- paulryanrogers 2y agoI wonder if we'll see assets being padded to some common byte sizes to combat this.
- kijin 2y agoNothing stops Cloudflare from inspecting the file contents, or using a hash to distinguish between identically-sized files. The only reason we assume they don't do this is because it's a waste of resources for no good reason. But what if somebody gave them a good reason?
- echoangle 2y agoAren’t the files end-to-end encrypted? How would they inspect the files?
- diggan 2y agoLast time I used Cloudflare I think their settings default to only "Origin SSL/TLS" (or whatever they call it), which wouldn't encrypt anything between Cloudflare and the origin, it would only encrypt data between Cloudflare and the end-user/browser.
- lolinder 2y agoBut the Signal client encrypts images before sending them to the Signal server. If it padded out the images at that point, the images would all be indistinguishable from each other unless Cloudflare were actually able to break the encryption (which would completely undermine the entire security model).
- diggan 2y agoAh yes, I'm sorry, I mistook the context. If Signal encrypts the images E2E, you're right that it wouldn't matter what Cloudflare does, especially if padded.
- xnorswap 2y agoIt could be useful for correlation. Say for example that you're an investigating agent in regular contact with someone. A single data-point wouldn't mean anything. However, a sequence of daily image retrievals might tell you that they spend 90% of their time in WA and 10% of their time elsewhere. That information alone still might not mean anything, but if you also have a specific suspect in mind, it may help confirm it. Or if you have access to the suspected person directly, if you're able to also befriend their "clean" profile, you might be able to pull the same trick and correlate the two location profiles. De-anonymisation isn't about single pieces of information, but all information helps feed into a profile to narrow suspects or confirm suspicions. ( By "agent" I just mean a person, not an AI agent nor Law enforcement, who could presumably just get the information more directly from cloudflare. )
- immibis 2y agoThere's probably at least a few instances where you send someone you think is American a picture but it gets cached in Moscow, or vice versa. Or you post a meme to a Californian left-wing group and it gets cached in DC. Not hard to imagine situations where getting an unexpected rough location could be a valuable signal.
- gruez 2y ago>Or you post a meme to a Californian left-wing group and it gets cached in DC. Not hard to imagine situations where getting an unexpected rough location could be a valuable signal. Not really. Any public meme group is inevitably going to be monitored by intelligence agencies, and you should assume as such. Even if it isn't, I can imagine agitators from the other side joining the group with a Russian VPN to poison the well. If there's a private group of people that you supposedly trust, any competent mole is going to be using device/network level VPN to cover their tracks. Otherwise they're 1 click away (eg. if someone shared a link) from an opsec fail.
- meowface 2y agoI would bet money almost no public meme groups are monitored by any intelligence agencies. And the few that are mostly only are just in the sense of being casually co-opted by state-sponsored trolls with almost no attention from actual intelligence agency staff (in the way this thread implies, with investigations and deanonymization and such).
- thrwaway1985882 2y ago"Near a user" is also a big assumption. I'm ~200 miles to ORD and ~500 to IAD, but my ISP's peering & upstream arrangements mean Cloudflare serves my traffic 700 miles from DFW. But, at the same time: Cloudflare isn't going to serve me a cache from Seattle, Manchester, or Tokyo. Pinning down an unknown Signal user to even a rough geographic location is an important bit of metadata that could combine to unmask an individual. Neat attack!
- btown 2y agoIt's also quite insidious as you don't need to control anything on any server to get this information; as long as you can get your target to load a unique URL never before loaded by anyone else, you can simply later poll it with an unauthenticated HTTP GET from different locations, and find which one reports a Cloudflare HIT (or, even if they hid that information, finding the one that returns with lower latency). If you're allowing user uploaded content, and you use Cloudflare as a CDN, you could mitigate and provide your users with plausible deniability by prefetching each uploaded URL from random data centers. But, of course, that's going to make your Cloudflare bill that much more expensive. Cloudflare could allow security-sensitive clients to hide the cache-hit header and add randomized latency upon a cache hit, but the latter protection would also be expensive in how many connections must be kept alive longer than they otherwise would. Don't do anything on a personal device or account if you want your datacenter to be hidden!
- ipaddr 2y agoGoing forward uploaded content should never go through cloudflaire and it never really needed to. Add unique urls. Maybe just avoid it altogether.
- gabeio 2y ago> Going forward uploaded content should never go through cloudflaire and it never really needed to. The problem in this case isn't cloudflare. The problem is that these images load without the user's interaction and the person sending it gets to choose if it's cloudflare or not. So your statement within this context doesn't really work.
- whoopdedo 2y agoSend picture to multiple accounts, perhaps on different services, the links that are cached at the same data center can be more confidently believed to be related.
- cyanydeez 2y agotiming and location can usually prune things down to enough data about a person.
- quotemstr 2y agoEven time zone leaks are privacy issues, and the leak we're discussing is more fine grained than time zone.
- dinosaurdynasty 2y agoIt only takes 33 bits to identify someone. This reveals a couple of bits.
- gruez 2y agoNot really. It's only true if the bits are uncorrelated, and you can acquire additional bits of information. I don't see how you can go from "this guy on the internet lives near Albuquerque, New Mexico" to "this guy is Walter Hartwell White, and lives at 308 Negra Arroyo Lane, Albuquerque, New Mexico, 87104" without massive opsec failures.
- chatmasta 2y agoRepeat the attack daily for a few weeks and you might get a pattern of movement. Of course if the target hasn’t left their general area then this won’t help. But if you’re a nation state watching a target move between multiple international locations, you could match this up with passport travel data to significantly reduce the anonymity set.
- gruez 2y agoSeems contrived. What type of a person cares about deanonymization attacks and nation-states trying to find him, but doesn't have an always-on VPN? Even without this attack, not using a VPN means you're 1 wrong click/tap away (if you accidentally clicked on a link) from leaking your IP.
- chatmasta 2y agoRight, agreed that VPN is the primary mitigation against this from a user perspective. But opsec is hard, especially when the attack can be triggered by a notification when the victim might not be expecting it and might not have VPN enabled (e.g. maybe they only enable VPN when using Discord). (But notifications are already a bad idea for opsec anyway.)
- 2y ago
- 65 2y agoI'd say it'd be useful for very specific use cases. Such as finding out what country Jia Tan, the XZ Utils backdoor attacker, is in.
- cassepipe 2y agoI wonder if it'd be a good idea for Signal to implement a "simple" mode that would deactivate most features in order to reduce the attack surface for people who really think they are being targeted. Would that be a good idea ?
- lxgr 2y agoIt's not stretching it. The expectation is that Signal does not reveal any observable aspect of your IP address or location when receiving messages on it. Whether this specific level/type of deanonymization is a problem for your particular use case is an entirely different question. Personally, I wouldn't even care if mutual contacts were to see my IP address outright (and they do for calls), but I'm not every user.
- pyeri 2y agoExactly. Especially when considering that Signal was often advertised as that *one* privacy friendly open-source messaging solution in a world dominated by data-collecting demons like WhatsApp, etc. I don't think even WhatsApp let's such status details leak; notwithstanding whatever they might be doing with the user data on the backend.
- sojournerc 2y agoI can send a link in Whatsapp to a domain I control and track if clicked. How is that different?
- lxgr 2y agoThe difference is that your target needs to actually click it. For this, they don't.
- genewitch 2y agoI don't care if users see "my" ipv4 because cgnat. I think i don't care if they can see my ipv6 because each machine gets a /64 to itself, that's the logic, right? But my PBX and my matrix server both use coturn. Our 10 user "private" PBX we have to VPN into a fortigate in a DC to use, but to my understanding, there's literally no way to eavesdrop on those calls without already compromising the server it's running on, and if that's the case, no extra VPN steps or whatever will help. anyhow even with a real, publicly routable IP, stock windows 11, stock macos (used to be true), and most linuxes won't get compromised by stuff like backorifice or whatever else l0pht put out as "remote administration tools". that is, there usually isn't any listening ports on a public IP these days. Shield's Up!
- hmottestad 2y agoIf I know someone on Signal I can now check if they’ve left the country. Or send this to a bunch of signal users whom you suspect one of them being a particular person, and if you know that the person you are looking for is going to travel you can send it once before and once after. Then see which of these users were in the home city and subsequently in the destination city.
- sojournerc 2y agoA VPN obfuscates this. Assuming a target is even remotely aware, you might think they are in Australia, while they're actually in Nova Scotia
- iforgot22 2y agoSay I send a message to someone who has a phone with push notifications enabled, showing message previews. Will the phone still be connected to the VPN when it wakes up to display the message? Because my iPhone doesn't seem to stay connected to my VPN when it sleeps, at least not reliably. There really should be a "never use the internet without VPN" mode on devices.
- sojournerc 2y agoValid point. Afaict, vpns I've used route all network activity regardless of phone state, but that's likely dependant on the service.
- iforgot22 2y agoI don't see how that can work for the push packet itself, cause I thought that's specially handled by some low-power hardware on the phone while the main parts are shut off. Unless that hardware is also managing the VPN connection, which I doubt. So if there's no always-on hardware maintaining that VPN connection, probably the phone is going to wake up without it. And even if it auto-reconnects, it'll probably load stuff before it's connected to the VPN.
- paulpauper 2y agoThis is not unique to signal. URL strings can contain identifying information regardless of where they are shared or posted. For example, if you send a link that ends with string of characters, these may correspond to a geographic location or browser settings. Blogger urls used to be geolocated, such as .ca for Canadian viewers. it is always safe to strip out unnecessary chacters if you're paranoid.
- dlandis 2y ago> attacker can use the cache geolocation method to pinpoint the recipient’s location Agree, good writeup, but also a stretch to say they are "pinpointing" anyone's location.
- ncr100 2y agoMmmm "qualified deanonymization" perhaps?
- harrall 2y agoWhen I was ~15 and this was ~2004, some friends and I ran a forum with a lot of users and did some bad things where we would track down repeat banned users and screw with them. (In our defense, they were screwing with us.) We used everything, from browser fingerprinting (and EFF only made the world aware of it 6 years later), looking them up in databases, tracing every digital evidence they left, etc. Every little thing counted. What I learned is that people leave a lot of traces and you can collect these traces to dox them. The way you write is even sometimes fairly identifiable.
- mmooss 2y agoCombined with other information, it may identify someone reliably, just like you can with zip code, age and gender. For example, if you know this person is part of a group with members in several locations, or if you can corroborate someone's movements, etc. For example, imagine someone suspected of sharing sensitive information with a journalist. They might have a short list of suspects, and use this technique to confirm which one it is. They might identify which journalist it is - maybe only a limited number cover this beat.
- cutemonster 2y agoOr you want to find a specific journalist, and you find out that they just arrived to a certain city, and there are only three hotels in that city...
- mmooss 2y agoThat doesn't tell you whether that journalist is investigating you. Identifying them as the recipient of a Signal message from a suspect is valuable information.
- cutemonster 2y agoI mean to assassinate
- mmooss 2y agoWhy are we talking about assassination?
- oceanplexian 2y agoThe real attack is that a law enforcement agency can trivially subpoena CloudFlare with the attachment URL they will hand over the IP address of the recipient of the image along with whatever other requests they made through the CDN which can pretty precisely and rapidly de-anonymize you.
- snapcaster 2y agoIt's leaking so many bits idk what else you would call it, deanonymization isn't a one shot thing and it's a spectrum not a binary outcome
- soerxpso 2y ago"Deanonymization" doesn't have to refer to a full exact address. There are people who wish to conceal which country or region they live in, which this cripples. There was a real example of that amount of information being relevant in the Silk Road investigation. Ulbricht accidentally revealed his timezone early on, which was useful to US authorities since it narrowed him down to being in the US, whereas without that information he could have been from anywhere in the world.
- alp1n3_eth 2y agoNot really. Anyone who wants to conceal what continent they're on will also be using a VPN 24/7, or will have the proxy setup in Signal (AKA running 24/7), which defeats this.
- lolinder 2y agoYep: If your threat model includes an attack like this and you're not always on a VPN already, you're likely already compromised. This is a neat demo, but it should not fundamentally alter the way that anyone is using Signal. Either it doesn't matter to you or you already have mitigations in place.
- bigiain 2y ago> If your threat model includes an attack like this The problem is, nobody's threat model includes state level attackers, until one day it does. Back when Ulbricht was publicly asking questions using an easily uncovered identity, he wasn't thinking that in a few years he'd have the full force of every relevant TLA in the US (and Five Eyes/14 Eyes) trying to track him down.
- lolinder 2y agoBut he also chose to go on and found a darknet narcotics service. Most people don't do something like that. Yes, it's vogue right now to speculate that what you're doing right now could suddenly become illegal in a new administration, but if that happens tomorrow, most of us would be one of hundreds of thousands who are all in the same boat. For that reason, most of us won't get targeted retroactively for behaviors that were legal at the time, and we have the option to reevaluate our security posture when the political landscape changes. But yeah, if you're actively speculating about starting an illegal service today, you should definitely have a better security posture than Ulbricht did.
- cekanoni 2y agoHeadline feels like a click bait :)
- bufferoverflow 2y agoCloudFlare has the actual IP address that viewed the image. Which means some powerful (or rich enough) actors can get it. This is very very bad.
- cthalupa 2y agoThis was... always, the case though? For any CDN service? How do you serve traffic to people without knowing where to send it?
- bufferoverflow 2y agoOnion protocol.
- endofreach 2y agoAgree. Though a valid concern might be that a victim uses signal because of E2EE, thinking no 3rd party involved in delivery, not knowing/thinking about a CDN used.
- iforgot22 2y agoLooks like it's possible to hit 2 datacenters due to load-balancing, which would narrow it down a bit more. Suppose you do this repeatedly as the target is moving around, hitting even more datacenters.
- antidamage 2y agoImagine sending a friend request to bin Laden's videographer and getting a reply from Pakistan while your entire military is looking for him in Afghanistan? There's definitely cases where this is going to be immediately used. Shit, just using it to scrape Cloudflare for additional metadata on everyone from other user table leaks is probably valuable data. Even triangulation over time as they move around is going to get a more precise result. Maybe you find a vulnerability that takes that cloudflare node offline and run it again, repeat until you've got a fairly small radius they could be in.
- KennyBlanken 2y ago> cached in a data center near that user Not necessarily. Cloudflare is very upfront that they do not cache everything, and the time things are cached can vary greatly. The kid keeps talking about "deanonymization" and he has no idea what the term actually means.
- nyclounge 2y agoFor that reason that's why federated setup such as matrix are better. It is much harder to deanonymiza a set of users on different servers in group chat.
- TacticalCoder 2y ago[dead]
- jcul 2y agoWhatsApp has an option to disable link previews. Surprised signal doesn't have this option. I only message people I know on Signal anyway. Edit: it seems signal does have the option
- vdqtp3 2y agoI had this same thought before reading the article - this isn't about link previews, it's about attachment caching
- mazambazz 2y agoBut previewing can involve automatically loading resources. This "attack" is very similar to CSRF in that your exploit involves making the victim load a specific resource. That's why in secure mail clients, nothing but plaintext should be rendered, and an optional "Load all resources" button is shown for when you trust the sender, and want to load any media elements that require HTTP onto your client. Signal could mitigate this with something similar, where it didn't load the image file AT ALL, and instead showed a message: <User> wants you to load an image from https://example.com/foo.png https://example.com/foo.png. Load image? > Yes > No
- vdqtp3 2y agoThe difference being is that it's not a resource controlled by the attacker, it's an attachment hosted by Signal. But yes, removing previews for everything would mitigate the issue.
- jeffhuys 2y agoDid you see the GIF? It's able to triangulate.
- tjoff 2y agoWhy does it need to be cached though? The only case where it might be downloaded more than once is if the user has multiple clients. Not that common and still very little traffic.
- rkagerer 2y ago[dupe]
- rkagerer 2y ago[dead]
- rkagerer 2y agoCaching attachments at a single nice, big, juicy honeypot like CloudFlare is one of the reasons Signal's privacy guarantees don't feel totally solid to me. I get that it's pragmatic, but feel there must be a better way. Does the caching occur even if both users are online when the attachment is sent?
- Gasp0de 2y agoWhy would cloudflare ever operate a data center that only one user at a time is ever near?
- BodyCulture 2y agoYou underestimate the value of this piece of information taken at different times. It can be enough to know in which country a person was yesterday or is today.
- AnonC 2y agoThis is quite a detailed write up. I went through the post quickly, but didn’t get why Signal would just download an attachment from an unknown number/contact without first prompting the user to accept or deny the conversation request. I’ve seen conversation requests always waiting for me to accept or not. If I don’t accept, I don’t see any messages on that chat and the other person doesn’t get any indication of message delivery. What have I missed? If the message is from a known or trusted contact, I think there can be larger problems than just a rough location reveal.
- hypeatei 2y ago> didn’t get why Signal would just download an attachment from an unknown number/contact Usability, most likely. Ultra-secure and paranoid doesn't result in good UX most of the time.
- powerhugs 2y agoPush notification thumbnails. It's mentioned in the article ...
- furyofantares 2y ago> I went through the post quickly, but didn’t get why Signal would just download an attachment from an unknown number/contact without first prompting the user to accept or deny the conversation request. I guess you went through the post too quickly, because it goes over how that's exactly how it works. Unless you have push notifications enabled and on default settings to include the content in the push notification.
- gruez 2y ago>I went through the post quickly, but didn’t get why Signal would just download an attachment from an unknown number/contact without first prompting the user to accept or deny the conversation request. Where are you getting the impression that signal auto-downloads attachments from an unknown number/contact? The OP says there's auto-download, but not that it happens from unknown contacts.
- hypeatei 2y agoThis is certainly an "attack" but not one you'd normally associate with zero click. There is no code execution, but some tricks to see which Cloudflare datacenter cached the image -- giving a very rough area the user is in. Impressive and insightful nonetheless.
- sim7c00 2y agodepending on the circumstance, the rough area might already be useful to adversaries of the person trying to hide. I wouldn't expect things like criminals etc. to suffer from this, 300 miles is a big radius for example... but if you want to know if 'the guy is still in country' or something like that (for instance law enforcement) it's useful for them. such parties could then collaborate with local resources to do further investigations. knowing which local resources in what area to enable might save a lot of 'costs'. as you said, impressive and insightful. :D kinda feel like the docs on it were a bit chatGPT aided, they are super clear and full of 'certain sentences'. (this is totally an excellent use-case for that, so not bashing on it at all!). nice read.
- sitkack 2y agoYou would know if they are over a cellular network or checking on mobile. If someone sends you a youtube link and you hit play, YT knows who you are, both from a network perspective and potentially the logged in user. If you are using signal in a high risk environment, you should be using it from a system that contains no extra information about you. This is the same posture one should take when using Tor. Basic opsec. I don't think these kinds of things are in signals threat model. It is meant? as a message platform for people with nothing to hide?
- sim7c00 2y agoi don't think you can call opsec basic, since it requires tons of knowledge about technology and techniques adversaries might deploy against you. targets of attacks don't neccesarily have this kind of knowledge. opsec is _incredibly_ hard for a person not deeply into technology and this type of information. you might argue that you need to stick with certain tools and techniques that are known good, but new vulnerabilities and techniques implemented against you can completely shatter previous knowledge on whats good and bad opsec and still break it despite doing it 'very well'. (like certain darknet markets being closed down due to new vulnerabilities being found in the platforms they use...) most people who rely on opsec/tradecraft for a living, also rely on teams of people to help them maintain it and validate it constantly... (or eventually fail and get bitten). you are right though that its unlikely a company or app producer would have a threat model tuned to people who want to hide stuff. those things generally tend to be closed down sooner or later. (encrochat and such services...)
- wood_spirit 2y agoPresumably cloudfare will close the loophole for enumerating cache edges now.
- a1o 2y agoThis is pretty interesting, and well documented. Great work! I wonder if there is a way to turn off notifications or if the approach is to simply not run such apps.
- omoikane 2y agoNot sure about mobile apps, but in Discord desktop there is an option under "settings -> notifications". Your browser may also have notification settings that would help. This changes the attack from a 0-click attack to a 1-click attack.
- squigz 2y agoThis doesn't strike me as a new 'attack' (I have to imagine there's even a name for such attacks), and 250 miles seems a large radius to 'deanonymize' someone, even a high-value target (even if such people didn't take any other measures to avoid being tracked...) For reference, here's a 250 mile radius around Toronto Canada https://i.imgur.com/ydpR0IZ.png https://i.imgur.com/ydpR0IZ.png
- Tepix 2y agoCongrats on finding this. Very impressive for a 15-year-old! The section "How to Protect Yourself" is lacking. Step 1. Don't receive this information in the push message. Only send the fact that there is something waiting for you in the app. Chances are there are other vulnerabilities that compromise the end-to-end encryption guarantees provided by the app (and only by the app). In Signal on iOS: Click on your icon in the top left corner. Click on settings. Click notifications. Click on display below "message contents". Make your choice. Another situation where convenience clashes with security, unfortunately.
- anon-3988 2y agoStep 2: If you use Discord, don't allow invites from _anyone_. Its quite bizarre why social media apps allow anonymous people to interact with you. 99% of the conversation I have is with people that I roughly know.
- ziddoap 2y ago>Its quite bizarre why social media apps allow anonymous people to interact with you. I mean, it's one of Discord's major use-cases. Joining a server of a common interest and meeting/talking with other people that share that interest.
- im3w1l 2y agoDiscord is for gamers and quite a lot of people will be playing a game and tell someone "add me on discord my tag is xyz". Not allowing invites would seriously cut into the usability.
- Marsymars 2y agoYou could have it so both people have to add each other before there's any indication that either person added the other. No extra work for person A, and the work for person B is just what person A had to do anyway.
- 2y ago
- gobip 2y ago"Signal instantly dismissed my report" "Telegram, another privacy-focused application, is completely invulnerable to this attack" "Discord […] citing this as a Cloudflare issue other consumers are also vulnerable to" "Cloudflare ended up completing patching the bug" I wish Signal would react differently. I still remember the bubble color controversy when they changed their mind after the backlash and not before. :-)
- airstrike 2y agoIs there really any difference between dismissing the report or "citing this as a Cloudflare issue"?
- debugnik 2y agoNot in practice. > There's clearly a problem here as Cloudflare says consumers are responsible for protecting themselves against these types of attacks, while consumers (ex. Discord) are putting the blame on Cloudflare.
- deleted 2y ago[deleted]
- nunobrito 2y ago[flagged]
- tptacek 2y agoYou're making this stuff up. In most threads about Signal, 1-2 commenters appear to post fabricated conspiracist stuff defaming the people who originally worked on Signal --- people extremely well-known to the real-world cryptography engineering community. I don't know why we're so chill about people being defamed here.
- nunobrito 2y ago[flagged]
- anon-3988 2y agoWouldn't other user that sees the other person's profile picture also drum up the cache? This wouldn't work for someone in a large server.
- doctorpangloss 2y agoI'm not sure how much if it makes any sense.
- Einenlum 2y agoThe attacker uses a patched version of Signal to be able to intercept requests and to block a get request to the attachment they have just created. At least it is my understanding.
- punnerud 2y agoThat’s just to be able to use their APIs to get the location of the sender. Example you used the normal Signal app without patch and sending me a message, and I have the patched version. Just to remove certificate pinning, to be able to see the API traffic because of encryption.
- sneak 2y ago[flagged]
- deleted 2y ago[deleted]
- open-sesame 2y agoUnless I'm missing something, this seems like an incredibly long winded way to check the users IP location? For example, connecting to a VPN and checking https://cloudflare.com/cdn-cgi/trace https://cloudflare.com/cdn-cgi/trace gives me `colo:CPH` (Copenhagen) which is far from my nearest CF datacenter (geographically), closer to the IP location from my VPN provider (Oslo) but still not particularly close? If I don't use a VPN, I don't even get the capital city of my country (which I'm in right now), I get a colo approx 250 miles north. So I also dispute that Cloudflare always returns the "nearest available datacenter". Don't get me wrong, the write up is cool and certainly interesting - just not convinced on the real world applications here...
- botanical76 2y agoDo you not buy that a user's IP location needs to be protected? There is a reason applications go to so much effort to proxy requests to resources such as images. It's not free to do this.
- ziddoap 2y ago>just not convinced on the real world applications here... As a piece of data alone, the results are probably not of significant use. The real-world application (and potential danger) is when this data is combined with other data. De-anonymization techniques using sparse datasets has been an active area of research for at least 15 years and it is often surprising to people how much can be gleaned from a few pieces of seemingly unconnected data.
- gruez 2y ago>The real-world application (and potential danger) is when this data is combined with other data. De-anonymization techniques using sparse datasets has been an active area of research for at least 15 years and it is often surprising to people how much can be gleaned from a few pieces of seemingly unconnected data. Seems pretty handwavy. Can you describe concretely how this would work?
- ziddoap 2y ago
- maverick74 2y agoWould be very interesting to see how other IM behave with this: For example: Jami - one of the most feature-complete, distributed IM...
- walkerbrown 2y agoNice work OP, and congrats on HN front-page. Keep publishing or it never happened!
- ryao 2y agoUsually, being identified as being part of such a huge group that there is no chance of being found is an example of anonymization, rather than deanonymization. The author might not like that there is any potential to narrow things down at all, but the information provided by this could be easily wrong if a VPN were used to have the traffic egress through a different geographic region.
- aimazon 2y agoWhat's old is new. Does anyone remember the forum signatures that would display the viewers IP address and location on a little wooden signpost held up by a troll-looking creature? https://cdn.geekzone.co.nz/images/forums/danasoftcache.jpg https://cdn.geekzone.co.nz/images/forums/danasoftcache.jpg
- alp1n3_eth 2y agoJust like the days of DoSing an IP from a COD Lobby
- deleted 2y ago[deleted]
- catlikesshrimp 2y agoThat was a troll feature. It usually showed any user his own information. MAYBE some forum doxxed users by posting their informatio? but I didn't see any.
- giancarlostoro 2y agoMy friend would figure out the username, but he never did it maliciously, just for the challenge. Forums would show you which user was viewing a thread...
- iforgot22 2y agoWikipedia still does if you aren't logged in
- giancarlostoro 2y agoHad a friend who made his own nice one, would then visit the thread, and figure out "who is viewing it" and show your username. ;)
- deleted 2y ago[deleted]
- kostadin 2y agoI was fascinated by this once I learned how it worked. At the time I was learning php and wrote a script that would draw graphics based on the requesting ip address and return as gif, then used that as my avatar on a few phpbbs. Learned a lot.
- yapyap 2y ago> it's possible for an attacker to run a cache geolocation attack to find out which local datacenter they're near--similar to how law enforcement track mobile devices through cell phone towers. very much disagree on this, they track mobile devices through your connection strength to multiple cellular towers while this attack proves which singular datacenter the victim is nearest. Don’t get me wrong the write up is really interesting but it does feel like the author is a bit of a sensationalist.
- some_furry 2y ago> Don’t get me wrong the write up is really interesting but it does feel like the author is a bit of a sensationalist. They claim to be 15 years old. Cut them some slack.
- r4victor 2y agoTheir twitter says > Joined November 2017 so likely a bit older :)
- some_furry 2y agoAh, that's true. They even have HackerOne activity from 8 years ago: https://hackerone.com/daniel/hacktivity?type=user https://hackerone.com/daniel/hacktivity?type=user So either they lied about their age then in order to join social media and they're some sort of child prodigy... or they're lying now.
- xnorswap 2y agoOr that hackerone account has been traded.
- hackermondev 2y agothat's a hackerone bug, that 8-year-old report is not mine :)
- spzb 2y ago
- alp1n3_eth 2y agoCool writeup with some interesting techniques and approaches! I'll echo the other comments and say "deanonymization" is stretching the definition of the word, along with "grab the user's location", as it isn't anything near precise. 150 miles is approx. a 2-hour drive on the highway from Atlanta, GA to Augusta, GA. In that radius, there's probably 700,000+ people. I do think the auto-retrieve attachment feature of Signal is slightly concerning, as for a private messenger I'd expect there to be an option to turn it off (like turning off JS in Tor). I don't know if I'm not looking deep enough, but there doesn't seem to be a feature for that. Signal appears to take a useful-by-default approach that balances privacy and ease-of-use in order to encourage adoption by the masses, I'd assume most people that are really concerned are hardening Signal, similar to what is in this guide: https://www.privacyguides.org/articles/2022/07/07/signal-configuration-and-hardening/#proxy-support https://www.privacyguides.org/articles/2022/07/07/signal-con... . They've always recommended a VPN / proxy + a modification of settings for more high-security scenarios. Caching isn't going anywhere, and neither is CloudFlare. The DoSing days of old in P2P multiplayer lobbies with exposed IPs seemed to carry more of a threat than this, CloudFlare's response seems to be the best out of the 3. Caching sensitive information is never recommended and the onus is on the application doing the communicating to tell their CDN / middle-service to not cache specific items.
- vel0city 2y agoYou can disable the auto-download. Settings > Data and storage > Media auto-download, you can choose what to auto download for mobile data/wifi/roaming.
- alp1n3_eth 2y agoThank you! That's what I get for quick scrolling through the settings. I for sure thought it would have been under Privacy (for this concern), but that makes sense too.
- LWIRVoltage 2y agoSo, just to confirm my understanding, if one goes into those settings and disables all auto-download, that helps- but, then a user will manually download images, correct? Are they still vulnerable to this issue then at that time?
- powerhugs 2y agoFor being 15 year old, cool work! But calling this de-anonymization is a stretch, if it can possibly pinpoint you within 250 miles (that's assuming geoip is correct too, which it rarely is). In their GeoGuesser demonstration video, the higlighted area is densely populated and you still would need to match millions of people vs the online user. It does provide some hints as to the location of the targeted user, and that is cool!
- nunobrito 2y agoIt is already more than enough to know which country to contact the authorities and to pinpoint a rough area where to look. If the scammer is in Nigeria, tough luck. If he is in the EU or US then exists a feasible chance to go after the person.
- SahAssar 2y ago> assuming geoip is correct too It's not using geoip, it's using anycast.
- deleted 2y ago[deleted]
- bmilleare 2y agoDe-anonymization would take monitoring over a period of time, but it could definitely work. Take this scenario for example: a person of interest is in the area of New York on Jan 1. On Jan 4 they travel to the UK. On Jan 7 they travel to Germany. On Jan 21 they travel back to the US. The list of suspects would be fairly small when US officials cross-check individuals that travelled US-UK on Jan 4 and Germany-US on Jan 21.
- eugenekolo 2y agoCan probably achieve the same level of deanonymization by just monitoring what times the user communicates most often. Or send them enough links that they'll click on.
- deleted 2y ago[deleted]
- treksis 2y agoimpressive
- _blk 2y ago[flagged]
- deleted 2y ago[deleted]
- LWIRVoltage 2y agoAm I correct in surmising that someone who uses aVPN on their phone, while sending Signal messages/ content, would be cloaked, provided the VPN server they pick isn't near them ?
- nunobrito 2y agoYes, that is correct. VPN near location would be disclosed, not yours.
- sitkack 2y agoYou could use this technique to see what geographic areas view what sites based on the content cache age, you would have to have the list of sites, but it would allow you to bucket a geographic by top sites from the test corpus.
- herczegzsolt 2y agoThe accuracy of this geolocalization depends very much on peering agreements. I don't know about the UD bit this will not be very accurate within the EU. As an example: In Hungary, there's pretty much only one peering hub (bix) and there's only one Cloudflare datacenter. You've already geolocated me better than this hack just by knowing my language or phone prefix.
- Einenlum 2y agoIt's not because you have a Hungarian number that you're not travelling somewhere else. I don't really understand the point.
- herczegzsolt 2y agoWhen I am traveling, i most likely use my mobile data. That data is tunneled to my mobile provider, exiting to the public internet at exactly the same server. In my case, Cloudflare will identify me as BUD even when i'm roaming at a different country. This behavior is very typical for the EU, because the telco landscape is fairly fragmented, and each company typically have only one, or at most 2 peering locations. This may be different within the US where the distances are bigger, and latencies matter more, so there is more incentive to peer locally.
- aaurelions 2y agoIf you need to deanonymize a user who moves around a lot, this method makes sense.
- nine_k 2y agoSo, it's like the [Spectre] attack against CPUs: trigger an access from a privileged context, check if the access has filled in some cache, infer privileged information from that. It seems that time and again, security-enforcing procedures assume that many functions they invoke are pure, but in reality these functions have side effects, and these effects are observable much easier than the security requires. The actual problem here that the secured area is only the stuff that came through the encrypted channel. Any access beyond it, like following a link, is obviously insecure. If the link was sent via the secure channel, it becomes even less secure because it allows to observe a correlation between the secure channel (otherwise impenetrable) and the insecure outside context, and allows to blow (some of) the cover. Opening links via Tor would mitigate it a bit. The hard truth here is that almost everything may have observable side effects, so opsec needs to permeate all aspects of life, the more cover you need, the fuller. This is mostly incompatible with a convenient UX, but, to be popular, a secure messenger has to be reasonably convenient. This necessarily limits the level of security attainable by its casual use. [Spectre]: https://en.wikipedia.org/wiki/Spectre_(security_vulnerability) https://en.wikipedia.org/wiki/Spectre_(security_vulnerabilit...
- Mystery-Machine 2y agoWhy does CloudFlare return whether it was a cache hit or miss? This information could be hidden/removed. I understand it's not a complete solution of the issue, because cached responses will return much faster than non-cached ones, but it's a step in the right direction.
- cesarb 2y agoIt seems to me that a key requirement for this attack is that both the attacker and the victim load the same link, that is, that the attacker knows the URL the victim is going to load. If Signal/Discord created a different link to be given to the victim, and never shared it with the attacker, this attack wouldn't work. That could be as simple as adding some extra pseudo-random parameters to the URL which will be ignored by the origin (but honored by the caches), or as complex as creating a completely separate URL for the receiver of the message, and somehow giving it to the receiver without giving it to the sender (easy on Discord, harder on Signal due to its end-to-end nature).
- layer8 2y agoSince creating separate URLs would largely defeat the purpose of caching, a simpler solution would be to just disable caching, as Cloudflare suggested in their response.
- udev4096 2y agoClever finding but the title does no justice to the actual attack. Even a bare minimum threat model requires a user to use VPN or Tor which completely eliminates your "0day". Signal rightfully declined your report because it's only job is to provide secure communication
- lxgr 2y agoSignal is definitely also aiming to provide metadata privacy, which they understand to be part of secure communication. Otherwise, they wouldn't pad attachment and message sizes, offer a "sealed sender" feature, allow relaying all calls to avoid callers/callees from learning users' IP addresses etc.
- mmooss 2y agoSignal is intended not for HN readers, but for ordinary people who don't understand VPNs and Tor.
- iforgot22 2y agoTypical mobile user with a VPN is still vulnerable as far as I can tell, because they may be disconnected while displaying a push notification, but feel free to prove me wrong: https://news.ycombinator.com/item?id=42786466 https://news.ycombinator.com/item?id=42786466
- udev4096 2y agoI have no idea about iOS but there have been past reports on it being extremely leaky and how apple basically white lists it's domains to bypass the VPN connection. Android doesn't suspend the VPN connection in any state, that's for sure
- iforgot22 2y agoAndroid seems to disconnect from VPN when sleeping, but I see Android has an "always on" option for VPN that'll block all non-VPN traffic until the VPN reconnects. So users have to make sure that's enabled.
- ementally 2y agoNot exactly the same type of attack, but very similar https://cyberinsider.com/timing-attacks-on-whatsapp-signal-threema-reveal-user-location/ https://cyberinsider.com/timing-attacks-on-whatsapp-signal-t...
- thayne 2y agoWhat is the benefit of caching images in a cdn for Signal? Assuming local client-side caching, the total number of requests for that resource should be very small, probably one in the vast majority of cases. On an unrelated note, it seems like CloudFront could very easily fix this by not returning the cf-ray header, or at least having an option for the customer to remove it. Although, it might still be possible to get that information based on timing information...
- dualogy 2y ago> the total number of requests for that resource should be very small "For that server" is the other number-of-requests..
- popcalc 2y agoSo that law enforcement can ask Cloudflare for the IP logs... Signal is a joke. https://simplex.chat/ https://simplex.chat/
- moe_sc 2y agoSignal claims to be a private, not anynomous, chat application. Theirt defaults are set so they can get mass market addoption, whilst beeing a big step up in privacy compared to the usual players in the space (like whatsapp and telegram). You simply won't be able to get the average user on apps that make use more complicated and apps like simplex doe exactly that. If you want Signal to be more secure, you can circumvent this attack vector by disableing auto downloads for media. I'm not saying Signal is perfect, there has been a bunch to critisize over the years. But why argue about use cases they never claimed to solve?
- modeless 2y agoYes, Cloudflare should allow customers to disable that header, and Signal shouldn't cache images sent to a single person, or even groups of less than a few hundred people.
- jrochkind1 2y agoI dont' believe the Signal app/network is choosing to cacheimages in a CDN? But any user can send anyone other user a message that includes a link to a CDN-cached resource. Isn't that the "attack" here? Or am I misunderstanding?
- moralestapia 2y agoPretty impressive work.
- maxrmk 2y agoCool! Contrary to some of the other posters I think this definitely counts as deanonymization, or at least is close enough. How anonymous would satoshi be today if we had his location to within 250 miles? Repeated applications of this attack (maybe disguised somehow?) could let you track someone’s travel over time, and it is usually only takes 4-5 zip code sized locations to uniquely identify someone.
- cenamus 2y agoHow many people live in a 250 mile circle around New York?
- everfree 2y agoI think the more important question is how many people in the world don't live within a 250 mile circle around New York? An investigator could potentially cut their geographical search down by 95%+.
- modeless 2y agoAlso the attack can be performed multiple times and if a person travels it could narrow down the possibilities quite a lot.
- vel0city 2y agoThey had an example of the attack getting two locations back, Las Vegas and San Francisco. So the target is somewhere in the many thousand square miles in the circle that encompasses almost half the US!
- sureIy 2y agoLet's say they travel between NY and LA, how many sources of data will you need to know who was in NY on a specific date and LA on a second date? Feels like only the government can reasonably locate that.
- kevindamm 2y agoThere was mention that the Teleport tool no longer works after the bugfix of the underlying issue (calling other cf locations via Workers and an internal subnet). It seemed like the ability to query which caches HIT on the dye-test image relied on being able to call out to each other DC. Without this control over the route (driving the probing of which caches were hit), the attack would no longer work, right?
- devmor 2y agoThere is another method to query the caches. This is mentioned in the article.
- kevindamm 2y agoAh, the VPN deployment which probes from various geographies? It has limited coverage (according to author, about 54% of all Cloudflare datacenters) but still a sometimes-working attack, granted. However, Cloudflare are known for being harsh on VPN exit points and the behavior of requesting the same (unique each pass) image from every geography and then never again, would probably look significantly suspicious, but yeah it seems not to be a priority for cloudflare at the moment.
- jdthedisciple 2y agowhy is the picture not simply cached near the sender as opposed to the receiver? is there any good reason for deciding this way on the part of Signal et al?
- pornel 2y agoThe attacker can't be forced to make a request. In this PoC the attacker disabled their own outgoing image requests. But that wouldn't help anyway, even if the image could be cached near the sender first, or the signal server prewarmed some other cache. After the victim opened the image, the attacker would see two locations that have the image cached, and could easily deduce which one is the victim's location (e.g. if Signal pre-warmed a random cache, repeating the attack a couple of times would be enough to eliminate the randomness).
- mmooss 2y agoIt's cached near the receiver for performance purposes, I assume, the same reason Cloudflare uses geographically local caches.
- kovariantenkak 2y agoLooking at the locations where Cloudflare has their servers [1] in the middle of Europe. With Geneva, Zurich and Munich there is definitely the possibility that this attack on Signal will leak whether someone is at home or not. I don't understand how Signal could dismiss this so easily. I'm starting get a bad feeling about their responses to these "low" stakes attacks. They already missed the ball on the database encryption mishap on desktop. [1]: https://www.cloudflare.com/network/ https://www.cloudflare.com/network/
- devmor 2y agoThis is an extremely cool avenue of attack, I love the bot/demonstration.
- croemer 2y agoCool writeup by a 15yo, except for the way it completely oversells in the title. Basically this allowed an attacker to find out which cloudflare data center a victim connected to when being tricked into loading something from cloudflare. This is often within a 250 mile radius of where they're living but not necessarily. Can't one find out someone's IP just as easily by making them make a request to a URL controlled by an attacker? Is the problem that cloudflare is whitelisted for 0-click?
- 9sIX3oZ1JB5 2y agoMight even argue that the title is good because it made us click
- AceJohnny2 2y ago> Can't one find out someone's IP just as easily by making them make a request to a URL controlled by an attacker? Unless you can find another flaw in Signal, that'd likely be a 1-click attack, which is less valuable than the 0-click attack demonstrated by the author.
- Kaibu 2y ago"Luckily" my ISP is DTAG which has horrible peering with Cloudflare. So I'm routed through Warsaw (WAW) most of the time, even though there are multiple closer datacenters in Germany.
- lxe 2y agoNot sure why so many top comments dismiss the severity of this. This is just exactly the type of attack that give law enforcement or a malicious actor a way to establish proof of whereabouts.
- byearthithatius 2y agoI would guess some are just jealous of his age, but some do find the claim of de anonymizing to simply be overblown given it doesn't tell you nearly enough to find anyone except in very niche cases. This "attack" is easily defeated with a VPN or living in any major city.
- gtsop 2y agoInteresting you touched on his age. I got extremely curious, why did the OP did such a flex?(assumming they are telling the truth). The first sentence is such a weird brag that it felt suspicious. The report is highly technical and extremely well written. We're either dealing with a pure genious or a fraud. But why would a genious flex? Doesn't make sense.
- adamrezich 2y agoI don't know what you think is genius about any of this, but you're right, the flex is odd. It's something I've been seeing more and more of lately, and I find it off-putting, because, Back In My Day, I never had such a phase, where I felt like I should be given more credit for my 1337 h4xx0r skillz, because I was in high school or whatever—and I don't remember anyone else doing it, either. I can only assume this is a consequence of modern social media having shifted the Internet from being a bunch of pseudonymous people making and sharing stuff, to everything being myopically focused on one's identity first, and what they do second (as is literally the case here). And it looks like it works to achieve its desired effect, too—a significant portion of the comments here are congratulating the guy for doing such a thorough technical write-up, given his age. Maybe this is just me being a grumpy “old” man now, but I would've found that condescending when I was his age, and would've rather concealed my age than be condescended to as such. But, to each his own, I suppose.
- jrochkind1 2y agoI guess signal preview-loading or remote-image-loading features are always going to be usable to identify broadly what region a user is in, using this attack. Can one disable those features in Signal? Would be annoying becuase they are nice, but yeah. If you don't want that attack to be able to locate you somewhat (or at least locate your internet endpoint, if you are using a VPN or something), you will need to turn off signal previews and network image displays. Right?
- honestSysAdmin 2y agoI guess I'm not so "crazy" for funneling all my Android's outbound traffic through a VPN that does two hops.
- Aachen 2y agoWhether that's crazy depends on your threat model. If there's no reason, it could still be crazy in the sense of protecting from an irrational fear. If you communicate with people or organisations who shouldn't know your location, it makes sense. It depends
- honestSysAdmin 2y agoIf you've ever been stalked by a crazy ex-girlfriend who is from a very rich family, you'll probably feel a little "paranoid" or whatever. I was already on the "I just want to be left alone" vibe generally before all that happened to me, so I just carried on as usual.
- ryanisnan 2y agoGreat job, you're going to go far Daniel.
- Einenlum 2y agoI guess one possible fix would be for cloudflare to implement an option to disable the x-cache header for unauthorised users. This way Signal devs could still check their setup by sending authentication headers. But it would solve the issue completely because you could always check the response time. Probably Signal should disable caching. I guess it's rare for someone to repeatedly download an attachment. Once it's there it's there. For grouped conversations it could be an issue though.
- Aachen 2y agoNot sure it's so rare. A large number of group chats will have people in the same area. For me it's the vast majority: family chat, groups of old classmates or flatmates are mostly in the same country, work chats too... I can think of one exception where a group member will consistently be hitting a different Cloudflare node from everyone else, but for everyone else, every time I send a picture into a group chat the caching will save traffic
- byearthithatius 2y agoI think its good for finding out if someone is still in a certain region. More like region identification not deanonymization.
- kelnos 2y agoWhy has Signal even enabled caching for those URLs? The most common case is going to be that the attachment is downloaded once, and that's it. I would even expect that Signal wouldn't allow you to download it more than once, and would immediately delete it after the first successful download. Well, ok, maybe the client fails mid-way through, so allow some grace period for a re-download. But I can't imagine that would be the common case either, and so disabling caching on their CDN would fix this issue, and hopefully not increase their costs much. At any rate, "deanonymization" is a bit clickbaity here. Narrowing someone's location to within 250 miles or so isn't great, but it doesn't deanonymize them. Edit: I didn't think about the case where an attachment is sent to a group chat, where multiple people will be downloading it. But in that case wouldn't the attachment be encrypted individually for each person in the group? I'm not sure how this works, of course.
- alp1n3_eth 2y agoSignal's default setup is more usability focused while supporting E2E, and less about tinfoil hat threat models about being present on a continent you're a citizen of. The items you mentioned can essentially be configured, for those that want the insane level of privacy / security. Messages can be auto-deleted 30 seconds after being seen, a proxy can be configured to route all your traffic through it, and tons of other things can be done to customize it more to the user's liking. I'd imagine they're caching it because of egress costs. File attachments, voice mail, video, etc. can all add up.
- mqus 2y ago> Signal's default setup is more usability focused while supporting E2E If images/attachments were e2ee, this problem probably wouldn't exist, right? or are the images on cloudflare encrypted? Edit: I should clarify. I didn't mean the encryption itself fixes the problem, but rather that: If this were handled like the text messages we send (not via cloudflare CDNs) then this wouldn't exist. I get that attachments are quite some bytes bigger than text but shouldn't the security guarantees be the same?
- 2y ago
- notatoad 2y agoThis is just the fundamental way the internet works, and is the reason that anonymizing proxies like Tor exist. If you don’t want people to be able to detect your rough geographic location, you should be using a proxy to hide it. For everybody else, knowing the edge server you are closest to is really not a threat.
- mmooss 2y agoPeople for whom it's a threat don't necessarily understand anonymizing proxies - very few do. Signal is supposed to provide security for those who do not.
- Aachen 2y agoWhere does Signal claim that, or who decides what they're "supposed" to provide? If wishes had wings, sheep would fly. People who want their computer to do a certain thing can also be expected to do a quick web search for how to make it do said thing. E.g.: hiding location? Use onion routing. Signal doesn't claim to hide your country (heck, they require your phone number!) so it seems wishful thinking to say they should have included e.g. a Tor client and enabled it by default
- deleted 2y ago[deleted]
- iforgot22 2y agoThere's a real difference between Discord itself knowing your location and any Discord user in the world knowing it. Just like there's a difference between the VPN provider knowing your ipaddr and every website you visit knowing it.
- perbu 2y agoNo, it isn't. This is Cloudflare passing exposing metadata when it really shouldn't. Having a configuration option or a origin response header akin to CloudflareCache: private or something is trivial for them to implement. The same information would then be available in the timing, but given the distributed nature here, that would be a lot harder to pull off.
- deleted 2y ago[deleted]
- moktonar 2y agoGuess what: you don’t need cloudflare
- joshfraser 2y agoIt's a classic timing attack. You can detect which Cloudflare datacenter is "closest" (ie. least network latency) to a targeted Signal or Discord user. The speed of light is the main culprit here.
- punnerud 2y agoIs he just 15? The level of technical details, and this part is not that simple: “quickly patched the Signal desktop app to remove SSL pinning and configured Burp to intercept and view HTTP requests/responses sent through the app”
- coffeeboy27 2y agoYou’d be surprised at how adept the younger generation can be, especially those who’ve grown up with technology. As tech evolves, so do they. There are kids who genuinely apply themselves, and because they’ve been immersed in this environment, it’s practically second nature to them. I remember the late 1990s: I was young, but more than anything, I was curious about how things worked, I had the luxury of time, and access to technology to explore it. I started coding in C++ when I was around 13, and honestly, I still feel like I started too late.
- iforgot22 2y agoThere are also a lot more kids doing this than before. Like, I was one of 12(?) students in our high school AP Comp Sci course, then just one year after, 120 students took the same course.
- deleted 2y ago[deleted]
- tga_d 2y agoA fun attack, but I don't think this is a significant improvement over the existing state of the art using delivery receipt timings ("Hope of Delivery"). https://arxiv.org/pdf/2210.10523 https://arxiv.org/pdf/2210.10523
- Havoc 2y agoSurprised that was only worth 200 bucks.
- unit149 2y ago[dead]
- rapatel0 2y agode-anonymization attack? - The information extracted is a rough 250 mile radius around the user - The attacker already has a way to contact the person (signal username / phone number) Intersting reading, but also seems like technical clickbait.
- flagos10 2y agoJust by the fact he's expressing distances in miles, I can say he's from USA. That's my 0-click deanonymisation. Nice attack otherwise.
- Funes- 2y ago>Just by the fact he's expressing distances in miles, I can say he's from USA. And you could be falling into his trap of getting you to believe so by expressing distance in miles, as well.
- ritcgab 2y agoImagining the cloudflare datacenters as cachelines and this is just like a side-channel attack like spectre. Not as fine-grained but still cool stuff.
- scottydelta 2y agoHow is it different than sending someone an image hosted on your server which is a tracking pixel and just get their IP+location? This will be more accurate than the cloudflare approach.
- quotemstr 2y agoYou can't instruct a random Signal client to fetch a random URL. Here's how this attack works: 1. Attacker sends novel image to Signal 2. Signal hosts the image on their core servers 3. Signal instructs victim to fetch preview of the image 4. Victim asks the CDN for the image 5. CDN gets the image from Signal core servers and caches it 6. Victim gets the image from the CDN and displays the preview normally 7. Attacker hits every one of the CDN cache servers 8. The CDN cache server that say "yep, saw that already" is the one closest to the victim
- scottydelta 2y agoCan't you already see the IP of the datacenter that requested the image from your server/pixel and map it to the data center+location? This is assuming the data center is directly requesting the source server which it might be given a few searches on Google [1]. [1] https://community.cloudflare.com/t/cloudflare-is-forwarding-me-datacenter-ips-for-some-reason-instead-of-real-user-ips/728910 https://community.cloudflare.com/t/cloudflare-is-forwarding-...
- 0xCMP 2y agoWell, unlike with tracking pixels, you are not in the direct request path and cannot block it. You also have no way monitor/log if it is happening (like you can in theory with a packet capture). It's obvious in hindsight, but I bet no one would have mentioned this possibility as why you should disable notification previews or that simply receiving a notification would possibly reveal this information.
- iforgot22 2y agoIf your target is savvy enough not to click random links sent by strangers, it's hard to get them to load it. Many apps have caught onto the tracking pixel technique. It used to work for iMessage long ago.
- tech234a 2y agoNote: this person is the same 15-year old who found the Zendesk Slack takeover exploit a few months ago [1]. [1]: https://news.ycombinator.com/item?id=41818459 https://news.ycombinator.com/item?id=41818459
- yaomtc 2y agoGiven the twitter account was made in 2017, they would have been eight: https://x.com/hackermondev https://x.com/hackermondev And that bug report to Adobe was made when they would have been five years old: https://hackerone.com/daniel?type=user https://hackerone.com/daniel?type=user
- aimazon 2y agoI think that's just a quirk of HackerOne's username system. The username daniel was previously owned by another account (now known as daniel-hamid) which submitted a bug to Adobe. If you go through @hackermondev's tweets (starting in 2018) they are without question a kid (making games in Roblox and Minecraft) and then started to show an interest in hacking in 2020 (which lines up with when they created their HackerOne account). The claim of being 15 years old is plausible (presumably with parents / guardians who are accomplished in technology).
- yaomtc 2y agoThanks for pointing that out, I missed the username change.
- iforgot22 2y agoHe'd be 8 when he made the Twitter account, not when he discovered that exploit. Pretty sure there are tons of 8yos with Twitter accounts.
- deleted 2y ago[deleted]
- ingohelpinger 2y agois simplex immune?
- mrbluecoat 2y agoAnyone send Snowden a push notification? Would be interesting to see if he's still in Russia...
- deleted 2y ago[deleted]
- AyyEye 2y agoCloudflare's business model is fingerprinting as a service. Awesome.
- aja12 2y agoI'm a bit at a loss there. Has _anyone_ ever considered Signal to be anonymous? Or Discord? If so, I have bad news: they are not anonymous. At all. Not even slightly anonymous. Nor did they ever claim to be, they only claim to not be able to read your messages (Signal claims that, I don't know about Discord, I doubt it). And that claim has flaws (sure the crypto is sound but have you thoroughly reviewed and compiled the version you are using right now?) At the very best, they are weakly pseudonymous, but that's about it. And yes, loading media by default has always been a staple of applications who prioritize their users' convenience at the expense of some security, a fine choice for the usual threat model of their users. And embedding media in messages has always been a staple of deanonymization attacks. So ok, the tracking pixel has been shown to still be a relevant technique today, that's nice but not surprising. If you want to remain anonymous though, don't use Discord or even Signal, and I'd advise against posting on HN either. Maybe, if you automate the pasting of messages (no js!) that has been reworded by a local llm from throwaway accounts through whonix, at random times that can't be correlated to your timezone, you _might_ have your chances. Don't bet on it. Anonymity does not exist any longer.
- upofadown 2y agoI am currently banned from the Signal subreddit for pointing out that we only have Signal's word that they don't collect metadata. So, yeah, people do consider Signal anonymous...
- iforgot22 2y agoPeople do use Signal and Telegram* in settings where anonymity matters. Sure they aren't meant for that, but there's no other widely-understood solution, and most of the time it's good enough for them. * Funny enough, not vulnerable this time because they use an in-house protocol, which is maybe even worse.
- deleted 2y ago[deleted]
- DirkH 2y agoPeople keep forgetting anonymous and private are two different things
- wkat4242 2y agoHmm "within 250 miles" is not deanonymization in my book. Unless you live in the middle of the desert. In which case there won't be a cloudflare DC near you anyway. It's nice but at most will give you an indication of city. Perhaps together with some additional OSINT you could find the user but you'll need a lot more clues. Well found though!
- 1oooqooq 2y agowhy signal even have that side channel??? even matrix encode image and other data in the e2e p2p message flow
- brikym 2y agoLooks like Cloudflare are still sending out the airport locations and hit status on the response headers. Maybe I'm missing something but it seems like if you had a large VPN network you could run a distributed query to figure out which edge nodes have cached the url.
- EthicalSimilar 2y agoThat’s exactly what the author does towards the end.
- oneturkmen 2y agoImpressive write-up, especially for your age! Thanks for sharing :)
- mimerme 2y agovery impressive findings
- donohoe 2y ago“deanonymization” Hardly. Amazing sleuthing but not deanonymization.
- pjjw 2y agothis is pretty devastating for signal
- Jean-Papoulos 2y ago"deanonymization" in this case is just plain wrong, you can't even tell which country the user would be in for sure. Also any proxy/vpn will completely protect against this. It's "a very rough estimation of a user's location when they are not using a vpn".
- sinuhe69 2y agoSo the default option of using onion routes to hide your IP and location still works.
- zorrolovsky 2y agoSo many comments get caught on the wording 'deanonymization'. Is there a standardized definition of 'deanonymization' accross industry experts, privacy-conscious people and hackers? For many commenters, it looks like deanonymization means unveiling highly sensitive info like name, address, email, etc. For privacy-conscious individuals and hackers, it looks like it means 'revealing a data point that shouldn't be revealed'. As a signal or Discord user, I would expect my country location not to be revealed to a person I don't know. So the latter definition makes sense to me.
- aimazon 2y agoAs you say, it depends on the person but I think for most people an acceptable definition is "deanonymization reveals PII". What qualifies as PII depends on the context/jurisdiction but typically an IP address would be considered PII whereas country (or a similar broad region) would not. https://en.wikipedia.org/wiki/Personal_data https://en.wikipedia.org/wiki/Personal_data
- khana 2y ago[dead]
- johnklos 2y agoI think all these things are absolutely ridiculous. I use alpine (the email client, not the Linux distro). Before that, I used pine. Every single thing that gets loaded from anywhere on the Internet has to be the result of an action that I take. Nothing ever gets loaded automatically. I get to choose if I load the thing using the server that I'm connected to, or if I load it directly on my local machine. I know the implications of each. The fact that programs, particularly ones that are supposed to be for the security minded like Signal, load anything by default, automatically, is just, well, naive. I can't be the only person who thinks that people who don't think these things through shouldn't be working on apps and email clients. Sure, people would have a cow if their email client didn't load every frigging thing and run remote Javascript and so on, but in Signal? Really? (end rant) I see that this can be turned off. I will now tell everyone I know that uses Signal that this should, in fact, be turned off.
- aucisson_masque 2y agoThat's a 15 year old. I can't even convince what the gouvernements are able to do. You could technically route signal over tor network but then even tor has vulnerabilities with it's C coding.
- UnreachableCode 2y ago2 questions - why do airports get cached with Cloudflare requests, and, if I use a VPN, am I getting content from my usual Cloudflare centre or the one from the country on the VPN I’m using?
- Uptrenda 2y agoI hate how teenagers can't help but post their age when it comes achievements like it makes them special. 'hai im 15 and i hack billion dollar companies in my spare time.' This is cringe AF. I don't care if they're "only a teenager." Presumably, the age was written to signal how le special they are and not liek other teenagers. So if you want special treatment learn how to be modest and don't over-exaggerate your achievements. Any adult who managed to read past this sentence is a bigger person than I am.
- carschno 2y ago> When a user sends an attachment (e.g., an image) on Signal, it is uploaded to cdn2.signal.org. Why is that even the case? I had understood that (binary) attachments are embedded into the encrypted message and hence transferred directly from sender to receiver. Obviously, retrieving media from an external location saves bandwidth at multiple positions. I am not a security expert, but it seems almost trivial to see how storing message data on an external server conceptually facilitates attacks like this one. Isn't that the same reason a link preview is generated at the sender first and then embedded into the message as an image?
- rozumbrada 2y agoI believe in reality it's a bit more complicated CDNs do not choose datacenters for users based on a geographic distance. The number one metric is latency but latency != physical distance. Second metric is optimizations of price of data transfer between peers and IXPs which results in very dynamic routing rules. Then consider also network/software hickups/maintanance and distribution of datacenters' load...
- littlecranky67 2y agoWhile not 0-click, this might work even better using DNS and a more dense network of anycast DNS servers delegating a subdomain. Send a link to the target, and the DNS resolve should end up at your anycast DNS server. Respond with a CNAME entry, triggering a second DNS request and you can determine at which DNS server the request was served. Would also work without anycast (and thus probably able to use a very dense botnet) and long list of NS entries for your domain.
- gwehrli 2y agoI remember iOS not always respecting VPN's do these notification attachments get loaded through a VPN?
- mixedbit 2y agoIf I use Signal or Discord to send someone a link to anything hosted on a server controlled by me, provided that the user opens the link, I will get an exact IP address of the user. IP address is much more useful in de-anonymizing the user than the nearest CloudFlare datacenter location.
- krupan 2y agoThat's why this is interesting, it doesn't even require someone to open a link
- teovall 2y agoIs there any reason other than debugging purposes that the cf-cache-status and cf-ray headers are included in every response? Why don't they remove those unless a debugging setting is enabled in the CloudFlare dashboard?
- beders 2y agoI think this is a valid observation and the affected apps should either add auth to resources they control - shared or not - or use an UUID to store it so names can't be guessed. This only works because the attacker knows the URL.
- deleted 2y ago[deleted]
- madcadmium 2y ago> This would provide an incredibly precise estimate of the user's location. Within ~250 miles of their location is not "incredibly precise"
- husamia 2y agothis highlights that the design of the protocols which are two decades old all need to be rethought