ContentsThe library

How a Message Stays Private

Hiding the Message Is the Easy Half, and a System That Only Hides It Can Be Taken Apart by an Attacker Who Never Reads a Word

Last timeAgreeing a Secret in Public

What actually happens to the shared secret: how it becomes several keys, what the cipher does with them, and why detecting tampering has to be built in rather than bolted on.

One secret into many keys

The previous lesson ended with both sides holding the same number. That number

is not used as a key.

It is put through a derivation step that stretches it into several independent

keys: one for each direction of the conversation, and historically separate

ones for encryption and for integrity. The derivation also mixes in values from

the handshake, so that two connections which somehow agreed the same secret

would still end up with different keys.

FIG 1From one shared value to the keys actually used
One number in, four independent values out, none of which can be used to find any other. The cost of the derivation is microseconds and the benefit is that a mistake anywhere is contained to one direction of one connection.

What the cipher actually does

The mental picture most people carry is a locked box. A more accurate one is a

very long tape of unpredictable bytes.

The key, together with a counter, generates a stream of bytes that looks random

to anybody without the key. The message is combined with that stream, byte by

byte, using an operation that undoes itself. The receiver, holding the same key

and counter, generates the identical stream and combines again, recovering the

message.

FIG 2Encryption as combining with a stream
the encrypted byte that travels on the wire
the message byte, which the attacker wants
the byte of key stream at that position, generated from the key and a counter
The operation is its own inverse, so combining the encrypted byte with the same key byte returns the message byte. That symmetry is the elegance and also the danger: it means the relationship between the encrypted text and the message is completely fixed once the stream is fixed, which is the subject of the next section.

Two consequences follow immediately and both matter.

The stream must never repeat. If the same stream position is used for two

different messages, combining the two encrypted texts cancels the stream out

entirely and leaves the two messages combined with each other, which is often

enough to recover both. This is why every message carries a counter that never

repeats under a given key, and why key reuse across connections is forbidden

rather than discouraged.

And the encrypted text is the same length as the message. There is no padding

and no rounding, which is convenient and is precisely why sizes leak as

described in the first lesson.

The lesson stops here

5 more paragraphs to go

You have read the opening. The rest of the argument, the problems that check whether it landed, and the lines worth keeping at the end all come with a plan.

The first lesson of every course in the library reads the whole way through, free, so you can see exactly what the rest of them are.

See the planThe contents

This is the reading half

Starting the course gives you your own copy of it. Every idea on every page has problems standing under it, marked with a reason rather than a tick, and any sentence you do not believe can be opened and argued with. None of that can happen on a page nobody owns.

The contents

The rest of this course

  1. 01Everything Is Encrypted and Somebody on the Wire Can Still Tell Which Page You Opened and Roughly What You Typed
  2. 02Two Strangers Shout Numbers at Each Other Across a Crowded Room and Walk Away Sharing a Secret Nobody Else Heardopening only
  3. 03Hiding the Message Is the Easy Half, and a System That Only Hides It Can Be Taken Apart by an Attacker Who Never Reads a Wordyou are here
  4. 04You Have a Perfect Unbreakable Secret Channel to Somebody, and Nothing So Far Has Said a Single Word About Whoopening only
  5. 05A Certificate Says One Narrow Thing, and Almost Every Belief People Hold About It Is a Guess Bolted On to That One Thingopening only
  6. 06Five Lessons of Separate Machinery Turn Out to Be One Conversation That Takes Two Messages and Is Over Before the Page Is Requestedopening only
  7. 07Somebody Is Recording Your Traffic Today in the Hope of Stealing a Key in 2031, and the Fix Is to Throw the Key Away Before They Get Thereopening only
  8. 08The Handshake Was Correct, the Cipher Is Sound, the Certificate Checked Out, and Your Data Is on Sale by Fridayopening only

Read alongside