3 ms·
My understanding of all DH based encrypted communication protocols is that they rely on some external authentication mechanism to ensure the public key of your
by rokob 3y ago
My understanding of all DH based encrypted communication protocols is that they rely on some external authentication mechanism to ensure the public key of your counterparty is actually the right person. Is that correct?
In other words, if my friend is on the other side of the world and we can only communicate digitally, I need to bootstrap trust in a public key somehow and that is always outside these protocols. This is specifically called out here in section 4.1 and I'm pretty sure this is just a fundamental reality but I wanted to see if anyone had pointers to either a general proof of this or some kind of alternative.
- maxloh 3y agoMaybe you can just video call him to make sure that the key is correct?
- janekm 3y agoIt seems we'll have convincing AI video impersonation before practical quantum cryptanalysis, unfortunately...
- seanhunter 3y agoThis attack has already happened in the wild apparently. I was speaking with a big company CISO a week ago who has just updated the runbook for their helpdesk to specifically introduce steps to mitigate it. Apparently the state of the hack right now is attackers are only generally able to convincingly fake a short section of video (because they will have limited source material of the person they are spoofing) so will call say a helpdesk on zoom with the faked video playing and say they are experiencing connection issues so are turning the video off. From then onwards they just fake audio which is a lot easier. The workaround/mitigation is for the service desk employee to insist at one or more random points in the call that the video has to go back on in order to do various additional authentication steps with video live. If the attacker has only built a short/shallow fake it will be very difficult for them to pass this.
- deleted 3y ago[deleted]
- filleokus 3y agoI believe this is true not only for DH based protocols, but more generally for all protocols without any pre-shared data over an insecure transport. Even quantum key distribution (QKD) is vulnerable to an active man-in-the-middle attacker. With no pre shared data, and a protocol which doesn't give (trustworthy) guarantees about who you are communicating with, it seems impossible to actually know if you are establishing a key with the intended recipient or not. I'm not aware of any formal proof of this however.
- csande17 3y agoYeah, the core issue is really that you can't cryptographically prove which human being is holding the cell phone you're talking to. You can't tell if you're talking to Bob, or someone named Charlie who is pretending to be Bob. Charlie could then hire an accomplice to call Bob and pretend to be you so you'd both think you were talking to each other. The threat model here assumes Charlie controls whatever mechanism you used to learn about Bob's phone number / public key / whatever, and that he can convincingly alter anything you say to Bob that involves checking whether you have the correct phone number / public key / whatever. Certificate Transparency type solutions make it easier to compare notes about whose phone number / public key / whatever is whose, but Charlie can still (with enough effort and resources) defeat them by impersonating everyone you try to talk to about Certificate Transparency.
- ylk 3y agoWhatsApp is working on improving this situation: https://engineering.fb.com/2023/04/13/security/whatsapp-key-transparency/ https://engineering.fb.com/2023/04/13/security/whatsapp-key-... Note: not trying to start a discussion on how much one can trust facebook