3 ms·
Google is using SSL with ECDHE which provides perfect forward secrecy. Having a copy of the SSL certificate won't do the NSA any good.
by zetafunction 13y ago
Google is using SSL with ECDHE which provides perfect forward secrecy. Having a copy of the SSL certificate won't do the NSA any good.
- vidarh 13y agoIt's not try it wouldn't do them any good. It just ensures that they can't use the cert to go back and look at old data streams and decrypt them. It doesn't prevent them from using a cert for man in the middle attacks, for example.
- kalmi10 13y agoBut of course one can't mitm all google traffic without someone noticing. (Discussion releated to this topic is getting quite redundant on HN. Same discussion in every thread.)
- cromwellian 13y agoChrome also uses ChannelID.
- duaneb 13y agoDoesn't help with MITM, only after the case.
- Amadou 13y agoHow hard would it be for the NSA to "partner" with the SSL accelerator manufacturers to add functionality that sends copies of all the ECDHE negotiated keys to the NSA so that they can decrypt most of the encrypted traffic that they captured off the backbones?
- lazyjones 13y agoOne of us is misunderstanding the definition of perfect forward secrecy. From what I understand, it protects past/current session keys if one private key is compromised in the future. It does not protect session keys after one key is compromised (e.g. the NSA has Google's private key) and certainly not when all private keys are compromised and the attacker can observe all handshakes etc. Agree/disagree?