You basically reverse-engineered it correctly. I've written up the full threat model, components and per-index leakage in one place here: https://news.ycombinator.com/item?id=48967481