ContentsThe library

How a Message Stays Private

The Handshake Was Correct, the Cipher Is Sound, the Certificate Checked Out, and Your Data Is on Sale by Friday

Last timeWhy Today's Secret Expires

A complete and correct encrypted channel leaves the metadata, the two endpoints, and everything the far end chooses to do with what you sent. Here is the honest list, and the whole course in one page.

What stays visible

The first lesson of this course listed what a watcher can see. The last lesson

returns to that list with everything in between completed, because the list has

barely changed.

An observer on the path still sees both addresses, the time the connection

opened and closed, every message size, the direction of each message, and the

total volume. In the common case they also see the name of the site, carried in

the first message so that one machine serving a thousand sites knows which

certificate to present.

That is a great deal. A record that a particular household connected to a

particular clinic, for eleven minutes, at nine in the evening, exchanging two

hundred kilobytes, is informative without a single decrypted byte. Analysts

have said plainly that metadata of this kind is often more useful than content,

because it is structured, small enough to process at scale, and does not need

reading.

FIG 1What a correct handshake protects
protectednot protected
the words of the request10
tampering with them in f10
which two machines are t01
when, for how long, how 01
the sizes and the patter01
what the browser does wi01
what the far end does wi01
Two rows protected and five not. The two marked rows are the ones that surprise people, because sizes feel like a technicality and the conduct of the far end feels like it should be covered by something, and neither is covered by anything in this course.

The shape of the traffic

Sizes deserve their own section because they are not a technicality. They are

content, slightly compressed.

A page load has a characteristic pattern. A first response of a particular

size, then a burst of resources of particular sizes, in a particular order,

with particular gaps. Different pages on the same site produce different

patterns. A classifier trained on captures of a few hundred candidate pages

then identifies which one was loaded from the encrypted traffic alone, and in

the published studies the accuracy is in the high eighties to low nineties.

Video is worse, in the sense of being easier. A streaming player fetches a few

seconds of video at a time, and the size of each fetch depends on how much

motion is in that part of the film, which makes a sequence of burst sizes

effectively a fingerprint of the title.

Typing is worse again. Keystrokes sent as they happen produce one small message

per character, and the gaps between them carry the timing of the typist, which

identifies both the person and, in some settings, the characters.

FIG 2One encrypted session, from four points of view
stepwho is watchingwhat they learnwhat they cannot learnhow hard it iswhat happened
1a casual observer on the pathboth addresses, the times, the volumethe wordsno effort, it is in the headersAvailable to anybody operating a network between the two machines, which includes the local one, the access provider, and everybody in between.
2an observer with a classifierprobably which page was fetchedthe wordsa few hundred training capturesRequires knowing the candidate set, which is usually easy because the site is known from the addresses.
3anything running in the browserthe plain text, the keystrokes, the sessnothingone installed extensionThe channel ends inside the browser, so anything with access to the page sees the decrypted content with no attack on the cryptography whatsoever.
4the far end and everybody it tellsthe plain text and your identitynothingno effort, you sent it to themThe largest exposure in the list, and the one the padlock is most often read as covering. It covers none of it.
4 steps
Read down the second column and the exposure grows while the effort falls. The wire is the hardest place to attack and the least rewarding, which is a useful way to allocate attention when thinking about where data actually gets lost.

Both ends hold the plain text

The channel is encrypted between two machines. At both of those machines the

data is plain, because it has to be, since the point of sending it was for

somebody to use it.

In the browser, the plain text sits in memory and is available to the page, to

every script the page loaded, to any installed extension with access to the

page, and to the operating system. On the server it sits in memory, usually in

logs, usually in a database, usually in a backup, and usually in whatever

analytics and error reporting services the operator has connected.

The lesson stops here

2 more paragraphs to go

You have read the opening. The rest of the argument, the problems that check whether it landed, and the lines worth keeping at the end all come with a plan.

The first lesson of every course in the library reads the whole way through, free, so you can see exactly what the rest of them are.

See the planThe contents

This is the reading half

Starting the course gives you your own copy of it. Every idea on every page has problems standing under it, marked with a reason rather than a tick, and any sentence you do not believe can be opened and argued with. None of that can happen on a page nobody owns.

The contents

The rest of this course

  1. 01Everything Is Encrypted and Somebody on the Wire Can Still Tell Which Page You Opened and Roughly What You Typed
  2. 02Two Strangers Shout Numbers at Each Other Across a Crowded Room and Walk Away Sharing a Secret Nobody Else Heardopening only
  3. 03Hiding the Message Is the Easy Half, and a System That Only Hides It Can Be Taken Apart by an Attacker Who Never Reads a Wordopening only
  4. 04You Have a Perfect Unbreakable Secret Channel to Somebody, and Nothing So Far Has Said a Single Word About Whoopening only
  5. 05A Certificate Says One Narrow Thing, and Almost Every Belief People Hold About It Is a Guess Bolted On to That One Thingopening only
  6. 06Five Lessons of Separate Machinery Turn Out to Be One Conversation That Takes Two Messages and Is Over Before the Page Is Requestedopening only
  7. 07Somebody Is Recording Your Traffic Today in the Hope of Stealing a Key in 2031, and the Fix Is to Throw the Key Away Before They Get Thereopening only
  8. 08The Handshake Was Correct, the Cipher Is Sound, the Certificate Checked Out, and Your Data Is on Sale by Fridayyou are here

Read alongside