ContentsThe library

How a Message Stays Private

Somebody Is Recording Your Traffic Today in the Hope of Stealing a Key in 2031, and the Fix Is to Throw the Key Away Before They Get There

Last timeThe Whole Handshake

What a stolen server key does to conversations that happened years earlier, why the old design handed over everything, and the one change that limits the damage to a single session.

The attacker who waits

Everything so far assumed the attacker wants to read the conversation now. One

adversary does not. Recording encrypted traffic is cheap, storing it is

cheaper, and neither the recording nor the question it answers has a deadline.

A terabyte holds a great deal of intercepted traffic and costs less than a

meal. So the useful threat model is this. The adversary captures the bytes

today, files them, and sets about obtaining the key by whatever route becomes

available over the following decade.

The routes are not hypothetical. A bug in a widely deployed library allowed

anybody on the internet to read the memory of a running server, private keys

included, and that bug was present for two years before anybody noticed. Keys

are also handed over under legal compulsion, taken in ordinary intrusions,

copied by departing staff, and left in backups and container images.

FIG 1One recording, over four years
stepwhenwhat the attacker doeswhat they can readwhat it cost themwhat happened
1todaycaptures the encrypted trafficnothinga diskNo attack on the cryptography is attempted. The bytes are simply kept, with the connection details and the certificate that was presented.
2next yearwaitsnothingnothingThe site renews its certificate, redesigns itself twice, and forgets the conversation ever happened. The recording is unaffected by any of that.
3in three yearsobtains the server private keydepends entirely on the designone bug, or one subpoenaThe fork in the lesson. Everything up to here is identical in both designs, and this is the step where they part.
4afterwardsattempts to decrypt the recordingeverything, or nothing at allan afternoon of computationUnder key transport, the whole archive opens. Under ephemeral key agreement, the key they stole was never used to protect any of it.
4 steps
Read the third column down and notice the last row is the only one that differs between the two designs. The attacker behaves identically either way, and the entire outcome was decided years earlier by how the session secret was established.

What one theft used to buy

The older design was straightforward and that is why it was chosen. The client

picked a random session secret, encrypted it to the public key in the server

certificate, and sent it. Only the server could decrypt it, so both sides now

shared the secret and the handshake was one message shorter.

The flaw is visible as soon as the recording attacker is admitted. The session

secret travels over the wire, protected by the server long-term key. Anybody

holding that private key later can take the recorded message, decrypt it,

recover the session secret, and from there decrypt everything else in the

conversation.

FIG 2The same theft under the two designs
Follow the two branches to the bottom row. The left branch turns one theft into a retroactive breach of unlimited size, and the right branch turns it into a problem that starts the day of the theft and ends when the certificate does.

Keeping it only for now

The property wanted can be stated in one sentence, and it is worth deriving

rather than memorising. A conversation should stay private even if every

long-lived secret in the system is later revealed.

Work out what that forces. If a secret is long lived, it must not be able to

recover the conversation key. If the conversation key cannot be recovered from

anything long lived, it cannot have been transmitted under a long-lived key,

and it cannot be stored anywhere after the conversation ends. So it must be

generated for this conversation, computed on both sides rather than sent, and

destroyed when the conversation closes.

That is exactly the key agreement of the second lesson. Each side generates a

private value, sends the public half, and both compute the same secret without

it ever crossing the wire. Add the deletion of the private values afterwards

and the property follows.

The lesson stops here

3 more paragraphs to go

You have read the opening. The rest of the argument, the problems that check whether it landed, and the lines worth keeping at the end all come with a plan.

The first lesson of every course in the library reads the whole way through, free, so you can see exactly what the rest of them are.

See the planThe contents

This is the reading half

Starting the course gives you your own copy of it. Every idea on every page has problems standing under it, marked with a reason rather than a tick, and any sentence you do not believe can be opened and argued with. None of that can happen on a page nobody owns.

The contents

The rest of this course

  1. 01Everything Is Encrypted and Somebody on the Wire Can Still Tell Which Page You Opened and Roughly What You Typed
  2. 02Two Strangers Shout Numbers at Each Other Across a Crowded Room and Walk Away Sharing a Secret Nobody Else Heardopening only
  3. 03Hiding the Message Is the Easy Half, and a System That Only Hides It Can Be Taken Apart by an Attacker Who Never Reads a Wordopening only
  4. 04You Have a Perfect Unbreakable Secret Channel to Somebody, and Nothing So Far Has Said a Single Word About Whoopening only
  5. 05A Certificate Says One Narrow Thing, and Almost Every Belief People Hold About It Is a Guess Bolted On to That One Thingopening only
  6. 06Five Lessons of Separate Machinery Turn Out to Be One Conversation That Takes Two Messages and Is Over Before the Page Is Requestedopening only
  7. 07Somebody Is Recording Your Traffic Today in the Hope of Stealing a Key in 2031, and the Fix Is to Throw the Key Away Before They Get Thereyou are here
  8. 08The Handshake Was Correct, the Cipher Is Sound, the Certificate Checked Out, and Your Data Is on Sale by Fridayopening only

Read alongside