4 ms·
I thought the point of forward secrecy in end-to-end encrypted messaging was to protect past conversations at the transport layer against the key being compromi
by wizeman 4y ago
I thought the point of forward secrecy in end-to-end encrypted messaging was to protect past conversations at the transport layer against the key being compromised?
In other words, the point being that a man-in-the-middle attacker cannot decrypt past conversations that he recorded even if in the future he is able to determine the key?
It's kind of obvious that you cannot prevent the other party from saving the messages, but from what I understand I don't think that's what forward secrecy is even trying to do (disclaimer: I'm not a cryptographer).
- kevdev 4y agoYou’re correct.
- upofadown 4y ago>I thought the point of forward secrecy in end-to-end encrypted messaging was to protect past conversations at the transport layer against the key being compromised? Yes. Exactly. Only the transport part is protected. Contrast, say, TLS with messaging. TLS is basically an encrypted pipe. Plaintext goes in and plaintext comes out. If someone saves some of that plaintext and it gets leaked, well, that isn't your job to prevent that but you can at least provide forward secrecy. After all, people don't normally save their sensitive web pages for extended periods of time... With messaging, saving old messages is more or less the default. When that happens the value of forward secrecy is negated. If you want your old messages to be gone, you (and your correspondent) actually have to get rid of them. >...man-in-the-middle attacker... Terminology quibble. I think this would be normally described as recording the encrypted messages off the wire. MITM implies than an attacker is impersonating one or more correspondents.
- wizeman 4y ago> Yes. Exactly. Only the transport part is protected. Well, isn't that valuable? > With messaging, saving old messages is more or less the default. When that happens the value of forward secrecy is negated. It's not negated because a passive attacker that records communications and then, in the (potentially far) future, somehow can obtain the key (say, by exploiting some weakness and/or brute-forcing), still cannot decrypt your past communications, regardless of whether everybody saves old messages or not. By passive attacker, I mean someone like the NSA, your ISP, your messaging provider, the server/P2P host that relays your messages, etc. > If you want your old messages to be gone, you (and your correspondent) actually have to get rid of them. But that's not what forward secrecy is designed to do, is it? It's designed to prevent third parties who can record the encrypted end-to-end communication from decrypting past messages when/if they can obtain your key. It's not designed for making old messages be gone. > Terminology quibble. I think this would be normally described as recording the encrypted messages off the wire. MITM implies than an attacker is impersonating one or more correspondents. Yes, sorry, I meant a "passive man-in-the-middle attacker".
- upofadown 4y ago>It's not negated because a passive attacker that records communications and then, in the (potentially far) future, somehow can obtain the key (say, by exploiting some weakness and/or brute-forcing), still cannot decrypt your past communications, regardless of whether everybody saves old messages or not. If someone breaks the encryption somehow then forward secrecy is also negated. They get the encrypted material directly. Forward secrecy is only effective in messaging if the attacker does something like break into your device to get the secret key material. At that point they will also get any saved messages that are still accessible to you, in whatever way they are accessible. Now in theory a messaging client could reencrypt old messages to something like a public key pair where the secret key material was protected by a strong passphrase. But no one does that because that would mean you would have to type in the passphrase whenever you wanted to see an old message. At that point you might as well just use encrypted email and leave everything encrypted all the time.