Xconfess/Xconfess
[Security/Privacy] Timing-correlation mitigation between post submission and on-chain anchor
Chiusa
#1338 aperta il 27 giu 2026
GrantFox OSSMaybe RewardedOfficial Campaigncontracthelp wantedprivacysecurity
Metriche repository
- Star
- (14 stelle)
- Metriche merge PR
- (Merge medio 18h 57m) (70 PR mergiate in 30 g)
Descrizione
Problem
If confessions are anchored to Stellar shortly after posting, an attacker correlating on-chain anchor timestamps with off-chain activity (IP logs, session timing) could de-anonymize posters.
Scope
- Audit the current anchoring flow for timing characteristics.
- Implement batching, delay, or timestamp jitter before anchoring.
- Consider aggregate/batch anchoring of multiple confessions per on-chain transaction.
Why it's hard
Requires balancing anchoring integrity guarantees against privacy, and reasoning about timing side-channels at the protocol level.
Acceptance criteria
- Anchoring no longer has a tight, predictable time correlation to submission time.
- Documented threat model showing the mitigation's effectiveness and limits.