ContentsThe library

How a Message Stays Private

You Have a Perfect Unbreakable Secret Channel to Somebody, and Nothing So Far Has Said a Single Word About Who

Last timeEncrypting the Bytes

Key agreement works beautifully and identifies nobody. This lesson builds the attack that exploits the omission, step by step, and shows why no amount of better cryptography fixes it.

The thing that was never promised

Read the guarantee from the second lesson again, carefully. Two parties who

exchange public values end up sharing a secret that a listener cannot compute.

Nothing in that sentence mentions identity. The guarantee is about the party at

the other end of the wire, whoever that turns out to be. If somebody else

answered, the exchange succeeds with them instead, and succeeds just as

perfectly.

This is not a weakness in the method. It is the exact scope of what the method

claims, and the method delivers it. The trouble is that people read the

padlock as a statement about identity, and the mathematics so far has made no

such statement.

FIG 1What each step has established so far
after key agreementafter encryption and tagestablished by anything
a shared secret exists100
the contents cannot be r110
the contents cannot be a110
the other party is who y110
The last row is empty across the whole table, and it is the row most people assume the first three imply. Note particularly the marked cell in the first column: after key agreement you share a secret with somebody, and the identity of that somebody has not been touched at any point.

Two perfect connections

The attack follows from the gap mechanically. An attacker who can place

themselves on the path does not break anything. They perform the protocol

correctly, twice.

FIG 2The attacker runs both halves
Count the cryptography that was defeated: none. Both halves used full-strength key agreement, full-strength encryption and valid integrity tags. The attack succeeds because two correct connections are indistinguishable from one, which is a question the protocol so far never asks.
FIG 3The same attack from three points of view
stepmomentthe reader seesthe attacker doesthe server seeswhat happened
11a connection opening normallyanswers in place of the servernothing yetThe reader typed the right name. The packets reached the attacker because of where the attacker sits, not because of anything the reader did wrong.
22a key agreement completingcompletes it, then starts a second one oa connection opening normallyTwo exchanges, each flawless. The attacker now has two different shared secrets and is the only party holding both.
33a padlock and no warningsdecrypts, reads, re-encrypts, forwardsan ordinary client connectionEverything the reader sends is in plain text inside the attacker machine for as long as it takes to forward. Passwords included.
44a page that works perfectlyalters one field on the way througha request it has no reason to doubtReading is the lesser half. The attacker is also in a position to change anything, and the integrity tags are recomputed by the attacker with the key the other side expects.
4 steps
Read the first and last columns on their own and both describe a normal, correct, secure session. Neither end has any evidence available to it that the other column exists. That symmetry is why the attack cannot be detected from inside the exchange.

Who is actually in a position

The attack needs position rather than brilliance, so the list of parties who

can run it is longer and more mundane than people expect.

Anybody operating a network the reader is on, which includes a cafe, an

airport, a hotel, an employer and a university. Anybody who has compromised a

router anywhere on the path. A resolver that answers the lookup from the first

lesson with the wrong number, which places the attacker at the destination

without touching the path at all. A network operator at the scale of a country.

And, routinely and legitimately, the inspection appliance an organisation

installs on its own network to read its own traffic, which is this exact attack

run with the consent of one side.

The lesson stops here

1 more paragraph to go

You have read the opening. The rest of the argument, the problems that check whether it landed, and the lines worth keeping at the end all come with a plan.

The first lesson of every course in the library reads the whole way through, free, so you can see exactly what the rest of them are.

See the planThe contents

This is the reading half

Starting the course gives you your own copy of it. Every idea on every page has problems standing under it, marked with a reason rather than a tick, and any sentence you do not believe can be opened and argued with. None of that can happen on a page nobody owns.

The contents

The rest of this course

  1. 01Everything Is Encrypted and Somebody on the Wire Can Still Tell Which Page You Opened and Roughly What You Typed
  2. 02Two Strangers Shout Numbers at Each Other Across a Crowded Room and Walk Away Sharing a Secret Nobody Else Heardopening only
  3. 03Hiding the Message Is the Easy Half, and a System That Only Hides It Can Be Taken Apart by an Attacker Who Never Reads a Wordopening only
  4. 04You Have a Perfect Unbreakable Secret Channel to Somebody, and Nothing So Far Has Said a Single Word About Whoyou are here
  5. 05A Certificate Says One Narrow Thing, and Almost Every Belief People Hold About It Is a Guess Bolted On to That One Thingopening only
  6. 06Five Lessons of Separate Machinery Turn Out to Be One Conversation That Takes Two Messages and Is Over Before the Page Is Requestedopening only
  7. 07Somebody Is Recording Your Traffic Today in the Hope of Stealing a Key in 2031, and the Fix Is to Throw the Key Away Before They Get Thereopening only
  8. 08The Handshake Was Correct, the Cipher Is Sound, the Certificate Checked Out, and Your Data Is on Sale by Fridayopening only

Read alongside