3 ms·
There is https://tools.ietf.org/html/draft-brown-pgp-pfs-03 https://tools.ietf.org/html/draft-brown-pgp-pfs-03 but I do not think that anyone implements it. Reg
by dependenttypes 6y ago
There is https://tools.ietf.org/html/draft-brown-pgp-pfs-03 https://tools.ietf.org/html/draft-brown-pgp-pfs-03 but I do not think that anyone implements it. Regardless I think that not having PFS is not necessarily a drawback.
> The Signal protocol (and entire Noise family of protocols including things like WireGuard) beg to disagree.
These use a dedicated key per device rather than per season.
- cyphar 6y agoThe proposal you linked is effectively a more formal version of the subkey PFS scheme I alluded to, though it looks like it tries to solve some of the issue with subkeys that make them not a good fit for PFS (though one issue I've had is that subkeys appear to be referenced by their index rather than their keyid, so deleting and replacing them can give you confusing messages on decryption). > These use a dedicated key per device rather than per season. For identity, not for encryption (in the PGP world this is the difference between the root key and subkeys -- though the root key cannot be used for encryption in this analogy). The keys used for encryption are rotated incredibly regularly (for each message in the Signal case, and every two minutes for WireGuard). That is what PFS looks like in asynchronous protocols.