6 ms·
It gets more interesting when you think about the impact on groups. Sending an image to a group is enough for all devices associated with that group to be ident
by bigbones 2y ago
It gets more interesting when you think about the impact on groups. Sending an image to a group is enough for all devices associated with that group to be identifiable from CloudFlare's side, who additionally see a giant chunk of unencrypted traffic from the same client addresses going to other web sites. Given Cloudflare's less-than-straight approach to sales, it is astonishing the words "secure" and "Signal" ever appear in the same sentence.
CloudFlare get to see a fuckton of metadata from private and group chats, enough to trace who originally sends a piece of media (identifiable from its file size), who reads it, when it is is read, who forwards it and to whom. It really doesn't matter that they can't see an image or video, knowing its size upfront or later (for example in response to a law enforcement request) is enough
- paulryanrogers 2y agoI wonder if we'll see assets being padded to some common byte sizes to combat this.
- kijin 2y agoNothing stops Cloudflare from inspecting the file contents, or using a hash to distinguish between identically-sized files. The only reason we assume they don't do this is because it's a waste of resources for no good reason. But what if somebody gave them a good reason?
- echoangle 2y agoAren’t the files end-to-end encrypted? How would they inspect the files?
- diggan 2y agoLast time I used Cloudflare I think their settings default to only "Origin SSL/TLS" (or whatever they call it), which wouldn't encrypt anything between Cloudflare and the origin, it would only encrypt data between Cloudflare and the end-user/browser.
- lolinder 2y agoBut the Signal client encrypts images before sending them to the Signal server. If it padded out the images at that point, the images would all be indistinguishable from each other unless Cloudflare were actually able to break the encryption (which would completely undermine the entire security model).
- echoangle 2y agoTLS doesn’t matter for End-to-end encrypted stuff though, you could exchange the data over Telnet and it would still be secure. The content itself is already encrypted before being transmitted and can only be decrypted by the receiver.
- kijin 2y agoAFAIK the attack described by OP only works if the attacker knows the (randomly generated) URL of the image, which probably means they have a Signal client that can decrypt the image already. So the secrecy of the content is not at issue. The question is whether some specific person has received the same image, and from where.
- chatmasta 2y agoPart of his attack requires disabling the cache on his (sender) side so that he doesn’t pollute the cache. That implies that both sides of the conversation share the same URL, which means Cloudflare could assume two IP addresses requesting the same URL on the Signal attachment domain are participating in a shared conversation.
- dingnuts 2y agoyeah, the person you're referring to is confused because the Cloudflare HTTP service terminates TLS and presents a Cloudflare certificate, but that doesn't have anything to do at all with Signal's E2EE which is not based on HTTPS PKI
- deleted 2y ago[deleted]
- greysonp 2y agoHi there, Signal dev here. We do, in fact, pad attachments to a limited set of bucket sizes.
- lolinder 2y ago> Given Cloudflare's less-than-straight approach to sales, it is astonishing the words "secure" and "Signal" ever appear in the same sentence. This is an overly binary take. Security is all about threat models, and for most of us the threat model that Signal is solving is "mainstream for-profit apps snoop on the contents of my messages and use them to build an advertising profile". Most of us using it are not using Signal to skirt law enforcement, so our threat model does not include court orders and warrants. Signal can and should append some noise to the images when encrypted (or better yet, pad them to a set file size as suggested by paulryanrogers in a sibling comment) to mitigate the risks of this attack for those who do have threat models that require it, but for the vast majority of us Signal is just as fit for purpose as we thought it was.
- crawfordcomeaux 2y agoHello, I'm an organizer for a system to coordinate multiple mutual aid networks, many of which are only organizing by Signal & Protonmail exclusively because they think they're secure and private. People who are doing work to help people in ways the state tries to prevent (like giving people food) rely on this tech. These are the same groups who were able to mobilize so quickly to respond to the LA fires, but the Red Cross & police worked to shut down. This impacts the people who are there for you when the state refuses to show up. This impacts the future version of you who needs it. Most people aren't disabled, yet. Doesn't mean they don't need us building infrastructure for if/when they become disabled.
- Evidlo 2y agoWhat groups did the police and Red Cross shut down? Any links?
- deleted 2y ago[deleted]
- basilgohar 2y agoIn any geopolitical crisis, you tend to have victims on both sides be prevented from getting relief, except when the one side is imperial. The powerful entities tend to prohibit relief to the oppressed side, even making it illegal.
- doodlebugging 2y ago>It gets more interesting when you think about the impact on groups. Sending an image to a group is enough for all devices associated with that group to be identifiable from CloudFlare's side, Doesn't this open up the possibility to identify groups that have been infiltrated by spies or similar posers? If you use this method to kinda-sorta locate or identify all the users in your group and one or more of those users ends up being located in a region where you should have no active group members then you may have identified a mole in your network. Just thinking out loud here since there's no one else home.
- gruez 2y ago>If you use this method to kinda-sorta locate or identify all the users in your group and one or more of those users ends up being located in a region where you should have no active group members then you may have identified a mole in your network. ...unless they happen to be using a VPN for geo-unblocking reasons or whatever.
- lolinder 2y agoIf you're in a group like this where people are seriously concerned about their location being discovered by governments or by their own contacts, anyone in that group who is not already on a VPN all the time is either ignorant or nuts.
- throwway120385 2y agoCommunication of any sort over any channel risks sharing location information. Silence is secrecy.
- KennyBlanken 2y ago> , it is astonishing the words "secure" and "Signal" ever appear in the same sentence. You misspelled "I do not understand what end to end encryption means"