Elektrine lite

← Feed

@markasspandi@fedi.fabrykajabo.li

Post #3145201

2025-01-21 22:29 UTC

@rysiek@mstdn.social Not to mention, from what I see this is kinda "easy" to fix if it's a journalist or other high-tier person: 1. Zero-click is based on push notifications, which can be disabled/show only name not actual content 2. In Signal settings you can turn off automatic download of Media files, which will mitigate the 1 click aspect too (Will still work after downloading file itself tho) And as always, if your thread model is high enough, you def should use VPN or TOR For regular users this doesn't really do much harm, assuming you don't have attackers specifically targetting you, and even if you did, cloudflare datacenters aren't much reliable source of exact location (author himself said ~250 miles radius). I still think this is an very interesting finding, and I believe signal should actually try to mitigate this somewhat instead of just saying it's not their responsibility, but I don't believe this is that severe.

Replies (1)

  • @rysiek@mstdn.social Also there is another way to look at: attacker also has no idea of knowing if the victim actually used vpn/tor So there is also uncertanity for the attacker Even if you know person is in a given country, you have no idea if they didn't set VPN also for the same country, which would show datacenter in the same country but different location

    Open ##3145202