this post was submitted on 23 Jan 2025
135 points (90.9% liked)

Technology

61024 readers
3851 users here now

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related content.
  3. Be excellent to each other!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, to ask if your bot can be added please contact us.
  9. Check for duplicates before posting, duplicates may be removed
  10. Accounts 7 days and younger will have their posts automatically removed.

Approved Bots


founded 2 years ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
[–] knightmare1147@lemmy.world 75 points 2 days ago* (last edited 2 days ago) (3 children)

Tldr: Someone can guess reasonably where you are by sending you a glitched friend request notification on your phone that tells the hacker what data center you're closest to.

It is pretty clever but I wouldn't call it full deanonymizing, should still get patched though.

good find by the tester.

Edit: used the term 'glitch' for simplicity of people reading, didn't mean to upset people; I'm just an amateur.

[–] CosmicTurtle0@lemmy.dbzer0.com 33 points 2 days ago (2 children)

It's not a glitched friend request notification.

It's a native friend request that you make through discord. The vulnerability lies in the attacker making a unique pfp for each request, forcing the CDN to cache the pfp at the closest data center to the user.

I would agree that it's not fully deanonymizing but it could resurrect tracking Elon and other billionaires.

[–] Petter1@lemm.ee 18 points 2 days ago

I like how you see the positive in bad news 😃

Don't we lnow wjere to shoot down their planes alreqdy? Or wait until they bribe washington officials?

[–] Fiery@lemmy.dbzer0.com 7 points 2 days ago

It's not even glitched, it's working as intended