You Have a Perfect Unbreakable Secret Channel to Somebody, and Nothing So Far Has Said a Single Word About Who
Last timeEncrypting the Bytes
Key agreement works beautifully and identifies nobody. This lesson builds the attack that exploits the omission, step by step, and shows why no amount of better cryptography fixes it.
The thing that was never promised
Read the guarantee from the second lesson again, carefully. Two parties who
exchange public values end up sharing a secret that a listener cannot compute.
Nothing in that sentence mentions identity. The guarantee is about the party at
the other end of the wire, whoever that turns out to be. If somebody else
answered, the exchange succeeds with them instead, and succeeds just as
perfectly.
This is not a weakness in the method. It is the exact scope of what the method
claims, and the method delivers it. The trouble is that people read the
padlock as a statement about identity, and the mathematics so far has made no
such statement.
| after key agreement | after encryption and tag | established by anything | |
|---|---|---|---|
| a shared secret exists | 1 | 0 | 0 |
| the contents cannot be r | 1 | 1 | 0 |
| the contents cannot be a | 1 | 1 | 0 |
| the other party is who y | 1 | 1 | 0 |
Two perfect connections
The attack follows from the gap mechanically. An attacker who can place
themselves on the path does not break anything. They perform the protocol
correctly, twice.
| step | moment | the reader sees | the attacker does | the server sees | what happened |
|---|---|---|---|---|---|
| 1 | 1 | a connection opening normally | answers in place of the server | nothing yet | The reader typed the right name. The packets reached the attacker because of where the attacker sits, not because of anything the reader did wrong. |
| 2 | 2 | a key agreement completing | completes it, then starts a second one o | a connection opening normally | Two exchanges, each flawless. The attacker now has two different shared secrets and is the only party holding both. |
| 3 | 3 | a padlock and no warnings | decrypts, reads, re-encrypts, forwards | an ordinary client connection | Everything the reader sends is in plain text inside the attacker machine for as long as it takes to forward. Passwords included. |
| 4 | 4 | a page that works perfectly | alters one field on the way through | a request it has no reason to doubt | Reading is the lesser half. The attacker is also in a position to change anything, and the integrity tags are recomputed by the attacker with the key the other side expects. |
Who is actually in a position
The attack needs position rather than brilliance, so the list of parties who
can run it is longer and more mundane than people expect.
Anybody operating a network the reader is on, which includes a cafe, an
airport, a hotel, an employer and a university. Anybody who has compromised a
router anywhere on the path. A resolver that answers the lookup from the first
lesson with the wrong number, which places the attacker at the destination
without touching the path at all. A network operator at the scale of a country.
And, routinely and legitimately, the inspection appliance an organisation
installs on its own network to read its own traffic, which is this exact attack
run with the consent of one side.
The lesson stops here
1 more paragraph to go
You have read the opening. The rest of the argument, the problems that check whether it landed, and the lines worth keeping at the end all come with a plan.
The first lesson of every course in the library reads the whole way through, free, so you can see exactly what the rest of them are.
See the planThe contentsThis is the reading half
Starting the course gives you your own copy of it. Every idea on every page has problems standing under it, marked with a reason rather than a tick, and any sentence you do not believe can be opened and argued with. None of that can happen on a page nobody owns.
The contents