3 ms·
Also, if such an actor was storing encrypted traffic as well, they could now easily decrypt this traffic en mass.
by Donald 9y ago
Also, if such an actor was storing encrypted traffic as well, they could now easily decrypt this traffic en mass.
- moondev 9y agoYikes.. So compromise a public wifi and MITM + store any traffic pointed at the affected domain(s), then simply sign up for their own ERP account, download the key and decrypt.
- willstrafach 9y agoOnly if PFS is not in use though.
- kbirkeland 9y agoMost public wifi hotspots I've seen are unencrypted, so there'd be no need to do a MitM - just be within range to decode the client and AP transmissions.
- moondev 9y agoEven on an unsecured network would the transmissions not be encrypted via tls from your computer to the server?
- lbtuda 9y agohttps://nsa.gov1.info/utah-data-center/ https://nsa.gov1.info/utah-data-center/
- tinus_hn 9y agoIf you use ephemeral keys, as you should, the contents of past encryption is still secure if the private key gets leaked. The encryption keys are newly generated each time, the certified private/public key pair is only used to validate these encryption keys belong to server that has the certified keys. This is called Forward Secrecy.
- mvkg 9y agoWith TLS, the symmetric encryption keys are always newly generated regardless of the cipher suite chosen; the difference with the ephemeral cipher suites is how the keys are communicated. Without forward secrecy, the client chooses the premaster secret, encrypts it with the server's public key, and sends it in the ClientKeyExchange message. With forward secrecy, the client receives signed ServerDHParams in the ServerKeyExchange and responds with ClientDiffeHellmanPublic in the ClientKeyExchange.