Theodor Schnitzler (Research Center Trustworthy Data Science and Security, TU Dortmund, and Ruhr-Universität Bochum)

Mobile instant messengers such as WhatsApp use delivery status notifications in order to inform users if a sent message has successfully reached its destination. We have shown that this standard feature opens up a timing side channel with unexpected consequences for user location privacy. Our results demonstrate that, after a training phase, a messenger user can distinguish different locations of the message receiver by measuring and analyzing the time it takes to deliver messages.

This talk will cover the set of experiments conducted during the project, from original ideas, some of which could not be followed, to the final measurement and evaluation setup we used to produce the results published in the paper.

Speaker’s Biography

Theodor Schnitzler is a postdoctoral researcher at the Research Center Trustworthy Data Science and Security at TU Dortmund University in Germany. He obtained a PhD in Information Security from Ruhr University Bochum, Germany in 2022. His research focuses on privacy aspects in online communication environments from both technical and user perspectives.

View More Papers

podft: On Accelerating Dynamic Taint Analysis with Precise Path...

Zhiyou Tian (Xidian University), Cong Sun (Xidian University), Dongrui Zeng (Palo Alto Networks), Gang Tan (Pennsylvania State University)

Read More

Cryptographic Oracle-based Conditional Payments

Varun Madathil (North Carolina State University), Sri Aravinda Krishnan Thyagarajan (NTT Research), Dimitrios Vasilopoulos (IMDEA Software Institute), Lloyd Fournier (None), Giulio Malavolta (Max Planck Institute for Security and Privacy), Pedro Moreno-Sanchez (IMDEA Software Institute)

Read More

dewolf: Improving Decompilation by leveraging User Surveys

Steffen Enders, Eva-Maria C. Behner, Niklas Bergmann, Mariia Rybalka, Elmar Padilla (Fraunhofer FKIE, Germany), Er Xue Hui, Henry Low, Nicholas Sim (DSO National Laboratories, Singapore)

Read More

Can You Tell Me the Time? Security Implications of...

Vik Vanderlinden, Wouter Joosen, Mathy Vanhoef (imec-DistriNet, KU Leuven)

Read More