Hiding the Message Is the Easy Half, and a System That Only Hides It Can Be Taken Apart by an Attacker Who Never Reads a Word
Last timeAgreeing a Secret in Public
What actually happens to the shared secret: how it becomes several keys, what the cipher does with them, and why detecting tampering has to be built in rather than bolted on.
One secret into many keys
The previous lesson ended with both sides holding the same number. That number
is not used as a key.
It is put through a derivation step that stretches it into several independent
keys: one for each direction of the conversation, and historically separate
ones for encryption and for integrity. The derivation also mixes in values from
the handshake, so that two connections which somehow agreed the same secret
would still end up with different keys.
What the cipher actually does
The mental picture most people carry is a locked box. A more accurate one is a
very long tape of unpredictable bytes.
The key, together with a counter, generates a stream of bytes that looks random
to anybody without the key. The message is combined with that stream, byte by
byte, using an operation that undoes itself. The receiver, holding the same key
and counter, generates the identical stream and combines again, recovering the
message.
- the encrypted byte that travels on the wire
- the message byte, which the attacker wants
- the byte of key stream at that position, generated from the key and a counter
Two consequences follow immediately and both matter.
The stream must never repeat. If the same stream position is used for two
different messages, combining the two encrypted texts cancels the stream out
entirely and leaves the two messages combined with each other, which is often
enough to recover both. This is why every message carries a counter that never
repeats under a given key, and why key reuse across connections is forbidden
rather than discouraged.
And the encrypted text is the same length as the message. There is no padding
and no rounding, which is convenient and is precisely why sizes leak as
described in the first lesson.
The lesson stops here
5 more paragraphs to go
You have read the opening. The rest of the argument, the problems that check whether it landed, and the lines worth keeping at the end all come with a plan.
The first lesson of every course in the library reads the whole way through, free, so you can see exactly what the rest of them are.
See the planThe contentsThis is the reading half
Starting the course gives you your own copy of it. Every idea on every page has problems standing under it, marked with a reason rather than a tick, and any sentence you do not believe can be opened and argued with. None of that can happen on a page nobody owns.
The contents