Elektrine lite

← Feed

@rysiek@mstdn.social

Post #3145169

2025-01-21 22:27 UTC

You can also: πŸ‘‰ turn off push notifications – this makes the attack rely on you clicking the chat to download the image πŸ‘‰ turn off read receipts – again, this makes it more difficult for the attacker to know when to ask the question they can only ask once per a specific period of time πŸ‘‰ use Signal over Tor or a VPN to obscure your actual location – the attacker would get the rough location of the exit node

Replies (3)

  • @rysiek@mstdn.social 2025-01-21 22:33

    Technical details tl;dr: - Signal (and other communication platforms) uses Cloudflare with caching enabled for media - one can check on which Cloudflare endpoints a given attachment URL got cached (one can use a VPN for this), giving them the ability to roughly geolocate users whose Signal downloaded the file - a doctored version of Signal (or whatever app) allows the attacker to send the message with an image, and extract the attachment URL to know what URL to check for having been cached

    Open ##3145170

  • @rombat@sfba.social 2025-01-22 00:02

    @rysiek@mstdn.social Any info if using a Signal proxy mitigates this, or is this specifically a client-level thing? Assuming the latter.

    Open ##3145191

  • @Orca@nya.one 2025-01-22 02:31

    @rysiek@mstdn.social Since China blocked Signal and many other services long ago, I'm already 24/7 on a "VPN" (traffic obfuscation proxy, to be precise) before I can use Signal (or this fedi instance). sigh

    Open ##3145198