A team of researchers has found that it’s possible to infer the locations of users of popular instant messenger apps with an accuracy that surpasses 80% by launching a specially crafted timing attack.

The trick lies in measuring the time taken for the attacker to receive the message delivery status notification on a message sent to the target.

Because mobile internet networks and IM app server infrastructure have specific physical characteristics that result in standard signal pathways, these notifications have predictable delays based on the user’s position.

The resulting classification accuracy based on the researchers’ experiments was:

  • 82% for Signal targets
  • 80% for Threema
  • 74% for those using WhatsApp