Elektrine lite

โ† Feed

@rysiek@mstdn.social

Post #2214775

2025-01-21 22:11 UTC

There's a "Signal deanonymized" thing going around: https://gist.github.com/hackermondev/45a3cdfa52246f1d1201c1e8cdef6117 Stay calm. Deep breaths. ๐Ÿ‘‰ while this is a real consideration, the only thing the attacker gets from this is a very rough (kilometers or tens of kilometers radius) location ๐Ÿ‘‰ other communication platforms that use any kind of caching CDN to deliver attachments are just as affected ๐Ÿ‘‰ you almost certainly should continue to use Signal, unless you specifically know that this is a big problem for you. #Signal #InfoSec

Replies (12)

  • @rysiek@mstdn.social 2025-01-21 22:20

    In other words, it's not great that this is possible, but nowhere near an immediate and present danger to anyone except a very very small group of people doing very very specific things. If you're in that group, you'd already known you are. You'd have someone to ask about this. And you'd almost certainly be using some other tools to anonymize yourself anyway. If that's not the case, then this is almost certainly not something to lose sleep over. Signal remains a safe choice of a secure IM. ๐Ÿ‘

    Open ##3145166

  • @sexybenfranklin@smores.town 2025-01-21 22:16

    @rysiek@mstdn.social If you're using a VPN, does Cloudflare still serve you content from a node you're physically closest to, or does it do it based on where your VPN is?

    Open ##3145176

  • @cinebox@hackers.town 2025-01-21 22:22

    @rysiek@mstdn.social Doxing all signal users by revealing they live somewhere on the surface of the planet earth

    Open ##3145200

  • @rysiek@mstdn.social Not to mention, from what I see this is kinda "easy" to fix if it's a journalist or other high-tier person: 1. Zero-click is based on push notifications, which can be disabled/show only name not actual content 2. In Signal settings you can turn off automatic download of Media files, which will mitigate the 1 click aspect too (Will still work after downloading file itself tho) And as always, if your thread model is high enough, you def should use VPN or TOR For regular users this doesn't really do much harm, assuming you don't have attackers specifically targetting you, and even if you did, cloudflare datacenters aren't much reliable source of exact location (author himself said ~250 miles radius). I still think this is an very interesting finding, and I believe signal should actually try to mitigate this somewhat instead of just saying it's not their responsibility, but I don't believe this is that severe.

    Open ##3145201

  • @mikefordays@mstdn.io 2025-01-21 23:00

    @rysiek@mstdn.social Also, using a VPN should mitigate this vuln.

    Open ##3145203

  • @rysiek@mstdn.social Highly recommend everyone read this. It is just the tip of the iceberg. An ad can do this.

    Open ##3145204

  • @Twitom@social.vivaldi.net 2025-01-21 23:03

    @rysiek@mstdn.social This is just from their IP address, right? iirc Signal calls are P2P by default unless disabled in settings. If something like this is a big deal to someone's threat model (e.g. a journalist in a country that doesn't really like journalists) then they should use Briar or Tails for secure communication, but I'm sure these people already know that. Signal is specifically made for easy privacy and security, not for anonymity.

    Open ##3145205

  • @diazona@techhub.social 2025-01-21 23:06

    @rysiek@mstdn.social It's an extremely well-written report, too! Thanks for sharing. (as other people have mentioned, I appreciate your measured response)

    Open ##3145206

  • @rysiek@mstdn.social I assume anyone with a serious threat model has turned off automatic link previews a long time ago, since it is a possible gateway for much more serious zero-click attacks using a zero-day exploit.

    Open ##3145208

  • @rysiek@mstdn.social "while this is a real consideration, the only thing the attacker gets from this is a very rough (kilometers or tens of kilometers radius) location" My understanding from the write-up is that it's *hundreds* of km

    Open ##3145209

  • @lattera@bsd.network 2025-01-21 23:44

    @rysiek@mstdn.social Good thoughts! you almost certainly should continue to use Signal, unless you specifically know that this is a big problem for you. If this is a problem for you, you could use Signal behind Tor.Then, the CDN cache is hit from a Tor exit node. It would be great if Signal also provided an Onion Service CDN. That way, no data leaves Tor (if configured to use Tor).

    Open ##3145211

  • @ireneista@adhd.irenes.space 2025-01-22 00:06

    @rysiek@mstdn.social also, like, the mitigation is to use Tor, frankly

    Open ##3145212