PogoWasRight.org

Menu
  • About
  • Privacy
Menu

Turning Signal App into a Coarse Tracking Device

Posted on May 20, 2020June 24, 2025 by Dissent

David Wells writes:

Signal Private Messenger’s ease of use, multiplatform support, and end-to-end encryption for both text and calls have attracted millions of users per day. Even Edward Snowden, the well known American Whistleblower, claims “I use Signal every day.”

So this month, when I disclosed a way to leak a user’s DNS server simply by ringing their Signal number (CVE-2020–5753), I was happy to see how fast they patched it. Revealing a Signal user’s DNS server can potentially reveal coarse location, but as we will later see, in instances such as Google Public DNS (8.8.8.8/8.8.4.4) and others, this attack can narrow the location down to the Signal user’s city due to usage of EDNS Client Subnet.

Unfortunately, at the time of this writing, the patch is not yet available on the Google Playstore or Apple AppStore, and due to our disclosure policy, we disclose issues once any patch or information pertaining a vulnerability goes public, such as this case.

Read more on Medium.

The disclosure policy is their policy, not law, and if they think it may put more people at risk to disclose this before the patch is available on Playstore or Appstore, then why the heck did they disclose it now?

No related posts.

Category: Featured News

Post navigation

← Tusla fined €75,000 for three GDPR violations
TSA tries again to impose an ID requirement to fly →

Now more than ever

Search

Contact Me

Email: info@pogowasright.org

Mastodon: Infosec.Exchange/@PogoWasRight

Signal: +1 516-776-7756

Categories

Recent Posts

  • Microsoft’s controversial Recall feature is now blocked by Brave and AdGuard
  • Trump Administration Issues AI Action Plan and Series of AI Executive Orders
  • Indonesia asked to reassess data privacy terms in new U.S. trade deal
  • Meta Denies Tracking Menstrual Data in Flo Health Privacy Trial
  • Wikipedia seeks to shield contributors from UK law targeting online anonymity
  • British government reportedlu set to back down on secret iCloud backdoor after US pressure
  • Idaho agrees not to prosecute doctors for out-of-state abortion referrals

RSS Recent Posts on DataBreaches.net

  • Scattered Spider is running a VMware ESXi hacking spree
  • BreachForums — the one that went offline in April — reappears with a new founder/owner
  • Fans React After NASCAR Confirms Ransomware Breach
  • Allianz Life says ‘majority’ of customers’ personal data stolen in cyberattack (1)
  • Infinite Services notifying employees and patients of limited ransomware attack
©2025 PogoWasRight.org. All rights reserved.
Menu
  • About
  • Privacy