Improving Signal's Sealed Sender - NDSS Symposium (2024)

Ian Martiny (University of Colorado Boulder), Gabriel Kaptchuk (Boston University), Adam Aviv (The George Washington University), Dan Roche (U.S. Naval Avademy), Eric Wustrow (University of Colorado Boulder)

The Signal messaging service recently deployed a emph{sealed sender} feature that provides sender anonymity by cryptographically hiding a message's sender from the service provider. We demonstrate, both theoretically and empirically, that this one-sided anonymity is broken when two parties send multiple messages back and forth; that is, the promise of sealed sender does not emph{compose} over a conversation of messages. Our attack is in the family of Statistical Disclosure Attacks (SDAs), and is made particularly effective by emph{delivery receipts} that inform the sender that a message has been successfully delivered, which are enabled by default on Signal. We show using theoretical and simulation-based models that Signal could link sealed sender users in as few as 5 messages.

Our attack goes beyond tracking users via network-level identifiers by working at the application layer of Signal. This make our attacks particularly effective against users that employ Tor or VPNs as anonymity protections, who would otherwise be secure against network tracing. We present a range of practical mitigation strategies that could be employed to prevent such attacks, and we prove our protocols secure using a new simulation-based security definition for one-sided anonymity over any sequence of messages. The simplest provably-secure solution uses many of the same mechanisms already employed by the (flawed) sealed-sender protocol used by Signal, which means it could be deployed with relatively small overhead costs; we estimate that the extra cryptographic cost of running our most sophisticated solution in a system with millions of users would be less than $40 per month.

View More Papers

(Short) WIP: End-to-End Analysis of Adversarial Attacks to Automated...

Hengyi Liang, Ruochen Jiao (Northwestern University), Takami Sato, Junjie Shen, Qi Alfred Chen (UC Irvine), and Qi Zhu (Northwestern University) Best Short Paper Award Winner!

Read More

ROV++: Improved Deployable Defense against BGP Hijacking

Reynaldo Morillo (University of Connecticut), Justin Furuness (University of Connecticut), Cameron Morris (University of Connecticut), James Breslin (University of Connecticut), Amir Herzberg (University of Connecticut), Bing Wang (University of Connecticut)

Read More

MINOS: A Lightweight Real-Time Cryptojacking Detection System

Faraz Naseem (Florida International University), Ahmet Aris (Florida International University), Leonardo Babun (Florida International University), Ege Tekiner (Florida International University), A. Selcuk Uluagac (Florida International University)

Read More

PrivacyFlash Pro: Automating Privacy Policy Generation for Mobile Apps

Sebastian Zimmeck (Wesleyan University), Rafael Goldstein (Wesleyan University), David Baraka (Wesleyan University)

Read More

Improving Signal's Sealed Sender - NDSS Symposium (2024)
Top Articles
(PDF) Introduction of Working Capital Management - PDFSLIDE.NET
Ten Steps To Creating A Solid Financial Plan For Yourself
Sdn Md 2023-2024
My Arkansas Copa
I Make $36,000 a Year, How Much House Can I Afford | SoFi
Paula Deen Italian Cream Cake
Braums Pay Per Hour
Culver's Flavor Of The Day Monroe
Best Restaurants Ventnor
Sports Clips Plant City
Christina Khalil Forum
Interactive Maps: States where guns are sold online most
Roster Resource Orioles
Csi Tv Series Wiki
Golden Abyss - Chapter 5 - Lunar_Angel
50 Shades Of Grey Movie 123Movies
ELT Concourse Delta: preparing for Module Two
Ahn Waterworks Urgent Care
Yisd Home Access Center
Www.paystubportal.com/7-11 Login
The Banshees Of Inisherin Showtimes Near Broadway Metro
Kitchen Exhaust Cleaning Companies Clearwater
Lbrands Login Aces
San Jac Email Log In
1964 Impala For Sale Craigslist
Pay Stub Portal
The Bold and the Beautiful
Shauna's Art Studio Laurel Mississippi
Bratislava | Location, Map, History, Culture, & Facts
Vitals, jeden Tag besser | Vitals Nahrungsergänzungsmittel
Foolproof Module 6 Test Answers
Gold Nugget at the Golden Nugget
Nsav Investorshub
Cpmc Mission Bernal Campus & Orthopedic Institute Photos
Obituaries in Hagerstown, MD | The Herald-Mail
Newsweek Wordle
Pink Runtz Strain, The Ultimate Guide
Booknet.com Contract Marriage 2
10 Types of Funeral Services, Ceremonies, and Events » US Urns Online
Darkglass Electronics The Exponent 500 Test
Dragon Ball Super Card Game Announces Next Set: Realm Of The Gods
Wood River, IL Homes for Sale & Real Estate
St Als Elm Clinic
Pronósticos Gulfstream Park Nicoletti
Great Clips Virginia Center Commons
Wera13X
Craigslist Cars For Sale By Owner Memphis Tn
Autozone Battery Hold Down
Asisn Massage Near Me
Who We Are at Curt Landry Ministries
Texas Lottery Daily 4 Winning Numbers
Supervisor-Managing Your Teams Risk – 3455 questions with correct answers
Latest Posts
Article information

Author: Geoffrey Lueilwitz

Last Updated:

Views: 6178

Rating: 5 / 5 (80 voted)

Reviews: 87% of readers found this page helpful

Author information

Name: Geoffrey Lueilwitz

Birthday: 1997-03-23

Address: 74183 Thomas Course, Port Micheal, OK 55446-1529

Phone: +13408645881558

Job: Global Representative

Hobby: Sailing, Vehicle restoration, Rowing, Ghost hunting, Scrapbooking, Rugby, Board sports

Introduction: My name is Geoffrey Lueilwitz, I am a zealous, encouraging, sparkling, enchanting, graceful, faithful, nice person who loves writing and wants to share my knowledge and understanding with you.