Theodor Schnitzler (Research Center Trustworthy Data Science and Security, TU Dortmund, and Ruhr-Universität Bochum)

Mobile instant messengers such as WhatsApp use delivery status notifications in order to inform users if a sent message has successfully reached its destination. We have shown that this standard feature opens up a timing side channel with unexpected consequences for user location privacy. Our results demonstrate that, after a training phase, a messenger user can distinguish different locations of the message receiver by measuring and analyzing the time it takes to deliver messages.

This talk will cover the set of experiments conducted during the project, from original ideas, some of which could not be followed, to the final measurement and evaluation setup we used to produce the results published in the paper.

Speaker’s Biography

Theodor Schnitzler is a postdoctoral researcher at the Research Center Trustworthy Data Science and Security at TU Dortmund University in Germany. He obtained a PhD in Information Security from Ruhr University Bochum, Germany in 2022. His research focuses on privacy aspects in online communication environments from both technical and user perspectives.

View More Papers

WIP: Infrared Laser Reflection Attack Against Traffic Sign Recognition...

Takami Sato (University of California, Irvine), Sri Hrushikesh Varma Bhupathiraju (University of Florida), Michael Clifford (Toyota InfoTech Labs), Takeshi Sugawara (The University of Electro-Communications), Qi Alfred Chen (University of California, Irvine), Sara Rampazzi (University of Florida)

Read More

Let Me Unwind That For You: Exceptions to Backward-Edge...

Victor Duta (Vrije Universiteit Amsterdam), Fabian Freyer (University of California San Diego), Fabio Pagani (University of California, Santa Barbara), Marius Muench (Vrije Universiteit Amsterdam), Cristiano Giuffrida (Vrije Universiteit Amsterdam)

Read More

Cryptographic Oracle-based Conditional Payments

Varun Madathil (North Carolina State University), Sri Aravinda Krishnan Thyagarajan (NTT Research), Dimitrios Vasilopoulos (IMDEA Software Institute), Lloyd Fournier (None), Giulio Malavolta (Max Planck Institute for Security and Privacy), Pedro Moreno-Sanchez (IMDEA Software Institute)

Read More

“I didn't click”: What users say when reporting phishing

Nikolas Pilavakis, Adam Jenkins, Nadin Kokciyan, Kami Vaniea (University of Edinburgh)

Read More