ContentsThe library

How a Message Stays Private

Everything Is Encrypted and Somebody on the Wire Can Still Tell Which Page You Opened and Roughly What You Typed

Before any of the machinery, the honest baseline: what a person watching the connection sees when every part of the encryption is working exactly as designed.

What each layer exposes

A packet is an envelope with a letter inside. The envelope carries the address

it is going to, the address it came from, how big it is and when it was sent,

and every machine along the way reads it. It has to. A network that could not

read the address could not deliver anything.

Encryption applies to the letter. This is not a limitation of current

technology and it is not going to be fixed in a later version. It is what

delivery requires.

FIG 1What a watcher on the path can read
readable by anyone on threadable by the network necessary for delivery o
the address at each end111
the size of every packet111
the time of every packet101
the contents of the mess001
the name of the site, hi110
The first marked row is the only one that encryption covers, and it is one row of five. The second marked row is the one that keeps being fixed and keeps coming back, because something has to tell the server which site is being asked for before a certificate can be chosen. Everything else is visible by construction.

The practical consequence is a sentence worth memorising. Somebody watching the

connection knows that you talked to this server, at these times, exchanging

packets of these sizes, in this order. They do not know what the packets said.

Precisely what is hidden

The guarantee is narrow and it is strong within its scope. A watcher cannot

read the contents, and a watcher cannot modify the contents without the change

being detected and the connection being aborted.

That second half is less celebrated and matters more often. An attacker who can

read your traffic is a privacy problem. An attacker who can change it, flipping

a bit in a page so that it loads a different script, is a complete compromise,

and the integrity half of the guarantee is what prevents that.

FIG 2One page load, as the reader sees it and as a watcher sees it
stepmomentwhat the reader didwhat the watcher sawwhat the watcher inferredwhat happened
10 mstyped a bank namea lookup for that exact name, in clear twhich bankThe lookup happens before any encryption exists, and traditionally travelled as readable text to a resolver chosen by the network. Encrypted lookups exist and are not the default everywhere.
242 msnothing, the browser connecteda handshake naming the site, partly in cwhich bank, confirmedThe first handshake message names the site so the server can pick the right certificate. Until recently this was unencrypted in every connection on the internet.
3310 mssigned intwo small packets out, one 14 kilobyte ra sign-in form was submitted and accepteThe sizes are characteristic. A failed sign-in returns a different sized page, so the watcher learns whether it worked.
4900 msopened the statements pagea 6 kilobyte request, then 31 packets towhich page, by matching the signatureThe watcher visited the same bank themselves and recorded what each page looks like in sizes. Matching is then a lookup.
4 steps
Not one byte of content was read, and the watcher has the bank, the fact of a successful sign-in, and which page was opened. This is the correct, fully working case. Nothing here is a bug in the encryption.

The shape of the conversation

The third and fourth rows above are the part people find surprising, so it is

worth being concrete about why it works.

Pages have size signatures. A page is a document plus a set of resources, each

of a particular size, fetched in a particular order. That combination is close

to unique within a site, and it does not change from visit to visit. An

attacker who wants to know which page you opened visits the site themselves,

records the signature of every page, and then matches.

FIG 3Accuracy of identifying which page was fetched, from sizes and timings alone
Figures of this order appear repeatedly in the published work on traffic analysis, against ordinary encrypted connections with everything configured correctly. The defence is padding, and padding costs bandwidth in proportion to how much it helps, which is why almost nobody deploys enough of it.

The sharper version of this attack targets things that are sent as you type. An

interface that sends a request per keystroke to offer suggestions produces one

small packet per character, and the size of each reply depends on how many

suggestions matched, which depends on what was typed. Published work recovered

search terms and, in one medical application, which condition a patient had

selected from a list, entirely from encrypted traffic.

The general rule is that any feature which turns user input into

differently sized network traffic leaks that input, and encryption does not

help because the leak is in the sizes rather than the contents.

The name, twice in the clear

Two places have historically given away which site you are visiting, both of

them before any encrypted channel exists.

FIG 4Where the name travels before anything is encrypted
The chicken and egg problem is the whole difficulty: the server needs the name to choose a certificate, and the name cannot be encrypted without a key, and the key cannot be agreed without a certificate. The modern answer publishes a separate key for the hosting provider in advance, which is why it requires the lookup to be secure first.

So the baseline is this. Somebody on the path knows which sites you visit, when

and for how long, how much you sent and received, and with decent probability

which pages you opened. What they do not know is what any of it said.

That is a worthwhile guarantee and it is smaller than the padlock implies. The

rest of this course is how even that much is achieved between two parties who

have never met, starting with the step that sounds impossible: agreeing a

secret while being watched.

Recap

  • Encryption hides the contents of the messages and nothing else: the addresses, the timing, the sizes and the direction of every packet stay in the clear by necessity.
  • The name of the site you asked for has historically travelled in plain text twice, once in the lookup and once at the start of the handshake, and only recently has either been fixable.
  • Sizes and timings alone identify which page of a site was opened, and in some designs which characters were typed, which is a real attack rather than a theoretical one.

This is the reading half

Starting the course gives you your own copy of it. Every idea on every page has problems standing under it, marked with a reason rather than a tick, and any sentence you do not believe can be opened and argued with. None of that can happen on a page nobody owns.

The contents

NextAgreeing a Secret in Public →

The rest of this course

  1. 01Everything Is Encrypted and Somebody on the Wire Can Still Tell Which Page You Opened and Roughly What You Typedyou are here
  2. 02Two Strangers Shout Numbers at Each Other Across a Crowded Room and Walk Away Sharing a Secret Nobody Else Heardopening only
  3. 03Hiding the Message Is the Easy Half, and a System That Only Hides It Can Be Taken Apart by an Attacker Who Never Reads a Wordopening only
  4. 04You Have a Perfect Unbreakable Secret Channel to Somebody, and Nothing So Far Has Said a Single Word About Whoopening only
  5. 05A Certificate Says One Narrow Thing, and Almost Every Belief People Hold About It Is a Guess Bolted On to That One Thingopening only
  6. 06Five Lessons of Separate Machinery Turn Out to Be One Conversation That Takes Two Messages and Is Over Before the Page Is Requestedopening only
  7. 07Somebody Is Recording Your Traffic Today in the Hope of Stealing a Key in 2031, and the Fix Is to Throw the Key Away Before They Get Thereopening only
  8. 08The Handshake Was Correct, the Cipher Is Sound, the Certificate Checked Out, and Your Data Is on Sale by Fridayopening only

Read alongside