https://eprint.iacr.org/2016/1013.pdf
See https://sgaxe.com/files/SGAxe.pdf for an attack that leaked Signal contacts.
https://eprint.iacr.org/2016/1013.pdf