CBR to avoid "uncovering" sniffing


Specialized software can figure out with good certainty what was said over a VBR encrypted stream without decrypting the stream by analyzing the ups/downs in the bitrate.

Paper by some engineering school - http://www.cs.jhu.edu/~cwright/oakland08.pdf

Paper by some other school (university) - http://www.cs.unc.edu/~fabian/papers/foniks-oak11.pdf

Could an option be added to force the use of CBR (Constant Bit Rate) on the server?

Encryption is nice, but if 90% of the conversation can be figured out by software...it's not very private.



