I hope the DIFF event is going well and there is a great exchange of ideas! With so many great minds gathered together this could be a good opportunity to discuss in the sidelines of the event the complex problems described in the above thread like traffic analysis attacks, which is considered a threat actively exploited in the real world, and the need for further research, and possible mitigation techniques, which other messaging apps are slow to address, DC could once again lead the way here!
Here is a quick summary of some references posted above:
The JASMINE documentation also explains that by analysing encrypted traffic “events” for a whole country – in mass interception mode – JASMINE has the ability to correlate and identify the participants in encrypted group chats on messaging apps … Such a metadata analysis system can record the distinctive network traffic pattern each time a phone receives a new encrypted message or notification from a chat application such as WhatsApp or Telegram. Over time, with dozens or hundreds of messages received, the correlation between these notification events for multiple individuals will get stronger.
Improving Signal’s Sealed Sender - NDSS Symposium
We show using theoretical and simulation-based models that Signal could link sealed sender users in as few as 5 messages.
Our attack goes beyond tracking users via network-level identifiers by working at the application layer of Signal. This make our attacks particularly effective against users that employ Tor or VPNs as anonymity protections, who would otherwise be secure against network tracing. We present a range of practical mitigation strategies that could be employed to prevent such attacks
This Undisclosed WhatsApp Vulnerability Lets Governments See Who You Message
The document makes clear that WhatsApp isn’t the only messaging platform susceptible. … “WhatsApp should mitigate the ongoing exploitation of traffic analysis vulnerabilities that make it possible for nation states to determine who is talking to who,” the assessment urged. “Our at-risk users need robust and viable protections against traffic analysis.” … WhatsApp’s internal security team has identified several examples of how clever observation of encrypted data can thwart the app’s privacy protections, a technique known as a correlation attack, according to this assessment. In one, a WhatsApp user sends a message to a group, resulting in a burst of data of the exact same size being transmitted to the device of everyone in that group. Another correlation attack involves measuring the time delay between when WhatsApp messages are sent and received between two parties — enough data, the company believes, “to infer the distance to and possibly the location of each recipient.”
Cracking Down on Dissent, Russia Seeds a Surveillance Supply Chain - The New York Times