@freddy@social.security.plumbing
Post #3145181
2025-01-22 07:54 UTC
@rysiek@mstdn.social @signalapp@mastodon.world excellent analysis. Fully agree that this attack doesn't match the average user's threat model and great suggestion that the probe can be eliminated by disabling read notifications. I would add that this is more of a Cloudflare bug. They should fix this.
Replies (1)
-
@rysiek@mstdn.social 2025-01-22 10:44
@freddy@social.security.plumbing @signalapp@mastodon.world I tend to agree, but I would expect Signal to push on them to fix this. And by "fix this" I mean "stop broadcasting cache status and POP site location in HTTP response headers all the time".