Ancestors

Written by Michał "rysiek" Woźniak · 🇺🇦 on 2025-01-21 at 22:11

There's a "Signal deanonymized" thing going around:

https://gist.github.com/hackermondev/45a3cdfa52246f1d1201c1e8cdef6117

Stay calm. Deep breaths.

👉 while this is a real consideration, the only thing the attacker gets from this is a very rough (kilometers or tens of kilometers radius) location

👉 other communication platforms that use any kind of caching CDN to deliver attachments are just as affected

👉 you almost certainly should continue to use Signal, unless you specifically know that this is a big problem for you.

[#]Signal #InfoSec

=> More informations about this toot | More toots from rysiek@mstdn.social

Written by Michał "rysiek" Woźniak · 🇺🇦 on 2025-01-21 at 22:20

In other words, it's not great that this is possible, but nowhere near an immediate and present danger to anyone except a very very small group of people doing very very specific things.

If you're in that group, you'd already known you are. You'd have someone to ask about this. And you'd almost certainly be using some other tools to anonymize yourself anyway.

If that's not the case, then this is almost certainly not something to lose sleep over. Signal remains a safe choice of a secure IM. 👍

=> More informations about this toot | More toots from rysiek@mstdn.social

Written by Leszek on 2025-01-21 at 22:29

@rysiek It depends.

What actually interests me is the response (or lack of it) from Signal. Seems like not much has changed over there in the last decade. Despite big words and hacker con keynotes they just want to be the new Facebook messenger.

Also there's an easier attack to get your exact egress IP address. It's good to be aware that just having Signal on your phone can reveal it (assuming notifications are enabled).

=> More informations about this toot | More toots from makdaam@chaos.social

Written by Avitus on 2025-01-21 at 22:41

@makdaam @rysiek There's nothing for them to say. It's a problem with CloudFlare, so CloudFlare needs to fix it.

=> More informations about this toot | More toots from Avitus@ioc.exchange

Written by Leszek on 2025-01-21 at 22:52

@Avitus CloudFlare doesn't mention any guarantees of anonymity of the audience.

Someone made a decision to use their services with all the implications of using it. So either nobody at Signal cares about exposing endpoint IPs (which I believe to be the actual stance - but like @rysiek said let's see if they respond) or they care and didn't check it when using CFlare as a dependency.

Either way it's the integrator's responsibility to check if the chosen components fit the purpose.

=> More informations about this toot | More toots from makdaam@chaos.social

Toot

Written by Avitus on 2025-01-22 at 00:28

@makdaam @rysiek CloudFlare already fixed the issue and Signal provided a statement to 404 Media: https://www.404media.co/cloudflare-issue-can-leak-chat-app-users-broad-location/

=> More informations about this toot | More toots from Avitus@ioc.exchange

Descendants

Written by Michał "rysiek" Woźniak · 🇺🇦 on 2025-01-22 at 00:38

@Avitus @makdaam Cloudflare fixed an issue that allowed the researcher to more easily target individual datacenters.

Signal's statement is behind a loginwall.

=> More informations about this toot | More toots from rysiek@mstdn.social

Written by Cassandra Granade 🏳️‍⚧️ on 2025-01-22 at 02:52

@rysiek @Avitus @makdaam IIRC, 404 uses a loginwall to prevent AI scraping, for the most part. Anyway, Signal's alleged statement from the article:

=> View attached media | View attached media

=> More informations about this toot | More toots from xgranade@wandering.shop

Written by Michał "rysiek" Woźniak · 🇺🇦 on 2025-01-22 at 10:33

@xgranade @Avitus @makdaam that's the statement from the gist. I'd like a statement directly from Signal somewhere.

=> More informations about this toot | More toots from rysiek@mstdn.social

Written by Cassandra Granade 🏳️‍⚧️ on 2025-01-22 at 10:43

@rysiek @Avitus @makdaam Of course agreed. Was only meaning that that's the quote 404 went with.

=> More informations about this toot | More toots from xgranade@wandering.shop

Written by Avitus on 2025-01-26 at 18:31

@rysiek @xgranade @makdaam Signal made a direct statement to the bug bounty hunter, which was provided to 404 Media and published. So the statement given to the bug bounty hunter is the statement from Signal.

=> More informations about this toot | More toots from Avitus@ioc.exchange

Written by Michał "rysiek" Woźniak · 🇺🇦 on 2025-01-26 at 18:35

@Avitus @xgranade @makdaam I would still like to hear more directly from Signal, not via the bounty hunter.

=> More informations about this toot | More toots from rysiek@mstdn.social

Proxy Information
Original URL
gemini://mastogem.picasoft.net/thread/113869174591941932
Status Code
Success (20)
Meta
text/gemini
Capsule Response Time
325.948242 milliseconds
Gemini-to-HTML Time
2.950038 milliseconds

This content has been proxied by September (3851b).