International Association for Cryptologic Research

International Association
for Cryptologic Research

CryptoDB

Kien Tuong Truong

Publications

Year
Venue
Title
2023
RWC
Three Lessons From Threema: Analysis of a Secure Messenger
We provide an extensive cryptographic analysis of Threema, a Swiss-based encrypted messaging application with more than 10 million users and 7000 corporate customers. We present seven different attacks against the protocol in three different threat models. As one example, we present a cross-protocol attack which breaks authentication in Threema and which exploits the lack of proper key separation between different sub-protocols. As another, we demonstrate a compression-based side-channel attack that recovers users' long-term private keys through observation of the size of Threema encrypted backups. From our analysis, we draw three wider lessons for developers of secure protocols.