5 ms·
Cool! Contrary to some of the other posters I think this definitely counts as deanonymization, or at least is close enough. How anonymous would satoshi be today
by maxrmk 2y ago
Cool! Contrary to some of the other posters I think this definitely counts as deanonymization, or at least is close enough. How anonymous would satoshi be today if we had his location to within 250 miles?
Repeated applications of this attack (maybe disguised somehow?) could let you track someone’s travel over time, and it is usually only takes 4-5 zip code sized locations to uniquely identify someone.
- cenamus 2y agoHow many people live in a 250 mile circle around New York?
- everfree 2y agoI think the more important question is how many people in the world don't live within a 250 mile circle around New York? An investigator could potentially cut their geographical search down by 95%+.
- modeless 2y agoAlso the attack can be performed multiple times and if a person travels it could narrow down the possibilities quite a lot.
- vel0city 2y agoThey had an example of the attack getting two locations back, Las Vegas and San Francisco. So the target is somewhere in the many thousand square miles in the circle that encompasses almost half the US!
- sureIy 2y agoLet's say they travel between NY and LA, how many sources of data will you need to know who was in NY on a specific date and LA on a second date? Feels like only the government can reasonably locate that.
- modeless 2y agoThe government is a plausible adversary for Signal
- int_19h 2y agoFWIW if it's the government, wouldn't they be able to just get direct access to Cloudflare logs - in real-time even - and thus observe and track the specific incoming connection to fetch the cached image?
- deleted 2y ago[deleted]
- kiwijamo 2y agoHow many people live in a 250 mile circle around their Cloudflare POP? Which Cloudflare POP I hit depends on which RSP I use. In the country I live in, our biggest RSP peers with Cloudflare in a neighboring country (as it is much cheaper for Cloudfare to send traffic via that RSP's peering exchange there). So something like 40% of traffic will seem to be from a entirely different country than reality. My RSP is a small RSP which until fairly recently only had two POPs in the entire country. So regardless of where you lived, customers of my RSP would have traffic exiting onto the internet via only one of two exit points. Rural users would seem to be coming from one of the two largest cities in my country even if they are easily >250miles way from their particular POP. They do peer with Cloudflare but obviously only at the locations where they and Cloudflare are in the same city (and I'm not sure this is the case -- it is possible all national traffic to Cloudflare traffic actually goes via the one POP in our biggest city). The only reason this attack identifies the city I happen to be in is because I live in the same city as my little's RSP's biggest POP and Cloudflare happens to peer with that RSP at that POP. Where I am is a large city so doesn't narrow things down very much -- but even worse is that whoever is looking for me would actually need to look anywhere in my country. I don't think I am an unique case as internet routing is rarely the most direct path for various technical, financial, political, etc reasons. De-anonymization is definitely stretching the reality of what this 'attack' is capable of IMHO.
- kachapopopow 2y agoYou can already do the same with advertisement ID in (almost) every single one of these applications.
- aimazon 2y agoThe counter point is that anyone who cares about being anonymous is using methods to disguise their identity that cannot be compromised by this attack, e.g: a VPN. Plus, there are much more effective versions of this attack, like sending a link to an endpoint that you control -- getting someone to click a link isn't hard if you're considered trustworthy enough to send them notifications. And less technical versions, like correlating when the user is online vs. offline with timezones around the world. The method that both Apple and Cloudflare use in their own privacy software (iCloud Private Relay for apple, WARP for Cloudflare) is specifically based on the idea that your region is not information that reveals your identity. If you enable Apple Private Relay, your origin IP will be obscured but the IP your traffic is routed through will be in the same country -- same principle. https://www.apple.com/icloud/docs/iCloud_Private_Relay_Overview_Dec2021.pdf https://www.apple.com/icloud/docs/iCloud_Private_Relay_Overv... This attack is academically interesting and novel but it's not "deanonymization".
- rosseitsa 2y agoI am not sure I understand what you mean by "trustworthy enough to send them notifications". Do you need anything other than one's phone number to send them a signal message?
- tEem21 2y agoThe recipient would need to have this enabled, though it is by default. You can deactivate allowing others to initiate chats with you from your phone number (Settings > Privacy > Phone number)
- tom1337 2y ago> The counter point is that anyone who cares about being anonymous is using methods to disguise their identity that cannot be compromised by this attack, e.g: a VPN. Yes unless Apple is doing Apple things and ignores VPNs for things like push notifications… https://x.com/mysk_co/status/1579997801047822336 https://x.com/mysk_co/status/1579997801047822336
- amyames 2y ago
- byearthithatius 2y agoStill quite anon. He almost certainly used a VPN, and if he didn't he likely lived in a major city which included thousands if not hundreds of thousands of capable engineers. If it said he was in SF during some messages that would tell us literally nothing.
- meowface 2y agoSatoshi's possible home IP address actually did leak shortly after Bitcoin's release, though it wasn't realized until years later. (It definitely may not be him and might instead be a random early user. But I think there's a moderate chance it's him.) Details: https://news.ycombinator.com/item?id=29728339 https://news.ycombinator.com/item?id=29728339 (I don't advocate attempting to find and publish his name and address, since it'd make his life difficult, but it's still very interesting in the abstract as a curious unsolved mystery for all these years despite the number of eyes on it.)
- kandesbunzler 2y ago... very anonymous because he was most likely using a VPN lmao