2 ms·
Session’s decision to remove forward secrecy is another big eyebrow-raiser. Signal is widely praised for its double ratchet precisely because it limits the dama
by estsauver 2y ago
Session’s decision to remove forward secrecy is another big eyebrow-raiser. Signal is widely praised for its double ratchet precisely because it limits the damage if a key is compromised. Session’s lack of PFS means that if your private key is ever exposed (or derived), all your past and future messages are fair game. For a messenger that aspires to anonymity or strong privacy guarantees, this is a major trade-off. I haven’t seen a convincing argument as to why the onion-routed approach can’t coexist with a forward-secure key ratchet.
- Hizonner 2y agoWhere you get into trouble with PFS is if you want to use the same identity on multiple devices, not when you want to use a relay/mix network. If all your devices can't communicate in a timely way and mutually agree on state, their ratchets get out of sync... and you can't guarantee that timely communication. For a lot of users, it's probably reasonable to drop forward secrecy to get multi-device support, and I believe that's Session's main reason for doing it. What I don't understand is why we have people who are so worried about forward secrecy, which protects you in relatively unusual circumstances, but not worried about traffic analysis, which is always a huge issue. From my point of view, this guy (or anybody) loses a ton of credibility when he says you shouldn't use a decentralized protocol, even with poorly quantified (but nonzero) resistance against traffic analysis, because it lacks PFS... and then turns around and suggests instead using Signal, which has exactly zero resistance against traffic analysis. For most real use cases, the traffic analysis is a vastly more important concern. I tend to think this is an example of how cryptographers get themselves into trouble by worrying about relative arcana, while declaring major practical attacks "out of scope". I could probably turn that into an NSA conspiracy theory at least as credible as the one in the blog post, although in fact I don't think there are any NSA conspiracies in play on any side here. Sounds like the Session people should clean up their code and enlarge their random seeds, though.