4 ms·
> Yes. Exactly. Only the transport part is protected. Well, isn't that valuable? > With messaging, saving old messages is more or less the default. When that
by wizeman 4y ago
> Yes. Exactly. Only the transport part is protected.
Well, isn't that valuable?
> With messaging, saving old messages is more or less the default. When that happens the value of forward secrecy is negated.
It's not negated because a passive attacker that records communications and then, in the (potentially far) future, somehow can obtain the key (say, by exploiting some weakness and/or brute-forcing), still cannot decrypt your past communications, regardless of whether everybody saves old messages or not.
By passive attacker, I mean someone like the NSA, your ISP, your messaging provider, the server/P2P host that relays your messages, etc.
> If you want your old messages to be gone, you (and your correspondent) actually have to get rid of them.
But that's not what forward secrecy is designed to do, is it? It's designed to prevent third parties who can record the encrypted end-to-end communication from decrypting past messages when/if they can obtain your key.
It's not designed for making old messages be gone.
> Terminology quibble. I think this would be normally described as recording the encrypted messages off the wire. MITM implies than an attacker is impersonating one or more correspondents.
Yes, sorry, I meant a "passive man-in-the-middle attacker".
- upofadown 4y ago>It's not negated because a passive attacker that records communications and then, in the (potentially far) future, somehow can obtain the key (say, by exploiting some weakness and/or brute-forcing), still cannot decrypt your past communications, regardless of whether everybody saves old messages or not. If someone breaks the encryption somehow then forward secrecy is also negated. They get the encrypted material directly. Forward secrecy is only effective in messaging if the attacker does something like break into your device to get the secret key material. At that point they will also get any saved messages that are still accessible to you, in whatever way they are accessible. Now in theory a messaging client could reencrypt old messages to something like a public key pair where the secret key material was protected by a strong passphrase. But no one does that because that would mean you would have to type in the passphrase whenever you wanted to see an old message. At that point you might as well just use encrypted email and leave everything encrypted all the time.