Somebody Is Recording Your Traffic Today in the Hope of Stealing a Key in 2031, and the Fix Is to Throw the Key Away Before They Get There
Last timeThe Whole Handshake
What a stolen server key does to conversations that happened years earlier, why the old design handed over everything, and the one change that limits the damage to a single session.
The attacker who waits
Everything so far assumed the attacker wants to read the conversation now. One
adversary does not. Recording encrypted traffic is cheap, storing it is
cheaper, and neither the recording nor the question it answers has a deadline.
A terabyte holds a great deal of intercepted traffic and costs less than a
meal. So the useful threat model is this. The adversary captures the bytes
today, files them, and sets about obtaining the key by whatever route becomes
available over the following decade.
The routes are not hypothetical. A bug in a widely deployed library allowed
anybody on the internet to read the memory of a running server, private keys
included, and that bug was present for two years before anybody noticed. Keys
are also handed over under legal compulsion, taken in ordinary intrusions,
copied by departing staff, and left in backups and container images.
| step | when | what the attacker does | what they can read | what it cost them | what happened |
|---|---|---|---|---|---|
| 1 | today | captures the encrypted traffic | nothing | a disk | No attack on the cryptography is attempted. The bytes are simply kept, with the connection details and the certificate that was presented. |
| 2 | next year | waits | nothing | nothing | The site renews its certificate, redesigns itself twice, and forgets the conversation ever happened. The recording is unaffected by any of that. |
| 3 | in three years | obtains the server private key | depends entirely on the design | one bug, or one subpoena | The fork in the lesson. Everything up to here is identical in both designs, and this is the step where they part. |
| 4 | afterwards | attempts to decrypt the recording | everything, or nothing at all | an afternoon of computation | Under key transport, the whole archive opens. Under ephemeral key agreement, the key they stole was never used to protect any of it. |
What one theft used to buy
The older design was straightforward and that is why it was chosen. The client
picked a random session secret, encrypted it to the public key in the server
certificate, and sent it. Only the server could decrypt it, so both sides now
shared the secret and the handshake was one message shorter.
The flaw is visible as soon as the recording attacker is admitted. The session
secret travels over the wire, protected by the server long-term key. Anybody
holding that private key later can take the recorded message, decrypt it,
recover the session secret, and from there decrypt everything else in the
conversation.
Keeping it only for now
The property wanted can be stated in one sentence, and it is worth deriving
rather than memorising. A conversation should stay private even if every
long-lived secret in the system is later revealed.
Work out what that forces. If a secret is long lived, it must not be able to
recover the conversation key. If the conversation key cannot be recovered from
anything long lived, it cannot have been transmitted under a long-lived key,
and it cannot be stored anywhere after the conversation ends. So it must be
generated for this conversation, computed on both sides rather than sent, and
destroyed when the conversation closes.
That is exactly the key agreement of the second lesson. Each side generates a
private value, sends the public half, and both compute the same secret without
it ever crossing the wire. Add the deletion of the private values afterwards
and the property follows.
The lesson stops here
3 more paragraphs to go
You have read the opening. The rest of the argument, the problems that check whether it landed, and the lines worth keeping at the end all come with a plan.
The first lesson of every course in the library reads the whole way through, free, so you can see exactly what the rest of them are.
See the planThe contentsThis is the reading half
Starting the course gives you your own copy of it. Every idea on every page has problems standing under it, marked with a reason rather than a tick, and any sentence you do not believe can be opened and argued with. None of that can happen on a page nobody owns.
The contents