Everything Is Encrypted and Somebody on the Wire Can Still Tell Which Page You Opened and Roughly What You Typed
Before any of the machinery, the honest baseline: what a person watching the connection sees when every part of the encryption is working exactly as designed.
What each layer exposes
A packet is an envelope with a letter inside. The envelope carries the address
it is going to, the address it came from, how big it is and when it was sent,
and every machine along the way reads it. It has to. A network that could not
read the address could not deliver anything.
Encryption applies to the letter. This is not a limitation of current
technology and it is not going to be fixed in a later version. It is what
delivery requires.
| readable by anyone on th | readable by the network | necessary for delivery o | |
|---|---|---|---|
| the address at each end | 1 | 1 | 1 |
| the size of every packet | 1 | 1 | 1 |
| the time of every packet | 1 | 0 | 1 |
| the contents of the mess | 0 | 0 | 1 |
| the name of the site, hi | 1 | 1 | 0 |
The practical consequence is a sentence worth memorising. Somebody watching the
connection knows that you talked to this server, at these times, exchanging
packets of these sizes, in this order. They do not know what the packets said.
Precisely what is hidden
The guarantee is narrow and it is strong within its scope. A watcher cannot
read the contents, and a watcher cannot modify the contents without the change
being detected and the connection being aborted.
That second half is less celebrated and matters more often. An attacker who can
read your traffic is a privacy problem. An attacker who can change it, flipping
a bit in a page so that it loads a different script, is a complete compromise,
and the integrity half of the guarantee is what prevents that.
| step | moment | what the reader did | what the watcher saw | what the watcher inferred | what happened |
|---|---|---|---|---|---|
| 1 | 0 ms | typed a bank name | a lookup for that exact name, in clear t | which bank | The lookup happens before any encryption exists, and traditionally travelled as readable text to a resolver chosen by the network. Encrypted lookups exist and are not the default everywhere. |
| 2 | 42 ms | nothing, the browser connected | a handshake naming the site, partly in c | which bank, confirmed | The first handshake message names the site so the server can pick the right certificate. Until recently this was unencrypted in every connection on the internet. |
| 3 | 310 ms | signed in | two small packets out, one 14 kilobyte r | a sign-in form was submitted and accepte | The sizes are characteristic. A failed sign-in returns a different sized page, so the watcher learns whether it worked. |
| 4 | 900 ms | opened the statements page | a 6 kilobyte request, then 31 packets to | which page, by matching the signature | The watcher visited the same bank themselves and recorded what each page looks like in sizes. Matching is then a lookup. |
The shape of the conversation
The third and fourth rows above are the part people find surprising, so it is
worth being concrete about why it works.
Pages have size signatures. A page is a document plus a set of resources, each
of a particular size, fetched in a particular order. That combination is close
to unique within a site, and it does not change from visit to visit. An
attacker who wants to know which page you opened visits the site themselves,
records the signature of every page, and then matches.
The sharper version of this attack targets things that are sent as you type. An
interface that sends a request per keystroke to offer suggestions produces one
small packet per character, and the size of each reply depends on how many
suggestions matched, which depends on what was typed. Published work recovered
search terms and, in one medical application, which condition a patient had
selected from a list, entirely from encrypted traffic.
The general rule is that any feature which turns user input into
differently sized network traffic leaks that input, and encryption does not
help because the leak is in the sizes rather than the contents.
The name, twice in the clear
Two places have historically given away which site you are visiting, both of
them before any encrypted channel exists.
So the baseline is this. Somebody on the path knows which sites you visit, when
and for how long, how much you sent and received, and with decent probability
which pages you opened. What they do not know is what any of it said.
That is a worthwhile guarantee and it is smaller than the padlock implies. The
rest of this course is how even that much is achieved between two parties who
have never met, starting with the step that sounds impossible: agreeing a
secret while being watched.
Recap
- Encryption hides the contents of the messages and nothing else: the addresses, the timing, the sizes and the direction of every packet stay in the clear by necessity.
- The name of the site you asked for has historically travelled in plain text twice, once in the lookup and once at the start of the handshake, and only recently has either been fixable.
- Sizes and timings alone identify which page of a site was opened, and in some designs which characters were typed, which is a real attack rather than a theoretical one.
This is the reading half
Starting the course gives you your own copy of it. Every idea on every page has problems standing under it, marked with a reason rather than a tick, and any sentence you do not believe can be opened and argued with. None of that can happen on a page nobody owns.
The contents