5 ms·
PSK isn't really a good solution, mostly because of scaling problems. Today, all you need is a 32-byte ECDH private key, and a corresponding 32-byte public key
by CiPHPerCoder 9y ago
PSK isn't really a good solution, mostly because of scaling problems.
Today, all you need is a 32-byte ECDH private key, and a corresponding 32-byte public key. To talk to any of the billions of devices on the Internet securely, all you need is their 32-byte public key, and some means to verify that it is authentic (i.e. certificate authorities + certificate transparency). With this information, you can calculate a shared secret (or use a sealing API given only their public key, if you really want).
Total local storage: PKI overhead plus your own keys, under a few megabytes.
Doing PSK at scale means storing billions of 32-byte binary strings. One for each participant you intend to communicate with. They must also do this for every possible device they wish to communicate with, otherwise others can just eavesdrop on their conversations if keys are reused.
You've turned an O(n) space problem into an O(n^2) space problem.
If your n is small, you might still be tempted to make the move, but it will quickly become unmanageable as n grows.
Furthermore, if a devices loses their key, you must:
1. Generate/share a new keypair with n devices (which at Internet scale is billions), and
2. Do so in a way that doesn't open the door for backdoors, which probably requires digital signatures and therefore you're not actually getting rid of public-key cryptography
I think at Internet scale, we're still years away from having reliable post-quantum cryptography to even recommend let alone adopt, but that's going to be the way to go. Something something baby and bathwater.
- staticassertion 9y agoThat's not N^2 it's N*k where k is number of devices and is generally very low. Most people will have at most 3 or 4 devices. You could also have a single key and store it on a wearable device, like a phone or watch, and we're back down to a single key per person. I think the bigger issue with PSK at scale is key generation and distribution.
- deleted 9y ago[deleted]
- IncRnd 9y agoIt's n^2 across all devices. You don't use the same key between two different pairs of parties.
- staticassertion 9y agoOhh, I see what you're saying.
- betterunix2 9y agoIn practice you would probably use something like Kerberos to avoid the quadratic overhead.
- IncRnd 9y agoAs long as the AES key size is 256 and not one of the 128 versions.
- colmmacc 9y agoPasswords are PSKs and are the overwhelming default authentication mechanism for Internet scale systems. Storing, distributing, and synchronizing billions of small blobs is actually a solved problem and not that big a deal. I wouldn't be so quick to write it off, because it has a real, working, easily understood invalidation and revocation story, which PKI does not. A system that combines asymmetric crypto public-private key pairs with the distributed-whitelist properties of simple passwords, by treating the public keys as PSKs, has a lot of compelling benefits.
- CiPHPerCoder 9y ago> Passwords are PSKs and are the overwhelming default authentication mechanism for Internet scale systems. Not for HTTPS, which is what we're talking about. For WPA2-PSK, okay, you have a small n, it might work. For user authentication against a local database, you're not encrypting, you're using validating against a password hash and then elevating the user's privilege for the duration of their session. That's far removed from what we mean when we say PSK (pre-shared keys), where encryption is implied.
- late2part 9y agoTo be fair, that’s what you’re talking about. I am mostly talking about SSH access.
- IncRnd 9y agoAre you aware of what forms of asymmetric crypto are broken by quantum computing?
- tscs37 9y agoPasswords are largely stored in servers with enough storage to deal with the users of them. However, distributing a PSK to every device is not friendly. 10 Million Passwords will at minimum take about 80 MB, some phones and IoT devices have only ten times of that as permanent storage or less. Passwords work mostly because the other side has the storage and cpu capacity to operate with them