3 ms·
Yes you are wrong :D If NSA is not actively man-in-the-middling you, Perfect forward secrecy still works. ECDHE has been in Openssl since version 1.0.0 so its
by peter487 13y ago
Yes you are wrong :D If NSA is not actively man-in-the-middling you, Perfect forward secrecy still works.
ECDHE has been in Openssl since version 1.0.0 so its out there just not used.
Btw. Is there any addon for Firefox that shows the “encrypted communication” details like google does?
- sliverstorm 13y agoThey don't have to take an active role though if they just sniff all the traffic, right?
- cturner 13y agoThey won't have access to the temporary keypair that the server generates, and which lives only on the server.
- tptacek 13y agoYes, they do.
- sliverstorm 13y agoWhoops. This wouldn't be the first time I got public/private key schemes muddled in my head.
- lazyjones 13y ago> Yes you are wrong :D If NSA is not actively man-in-the-middling you, Perfect forward secrecy still works. OK, I guess I was reading too much into the (not very enlightening) definition of PFS on Wikipedia and too little of the actual implementation based on Diffie-Hellman, which has the desired properties. The question that arises is: how feasible is a MITM attack on this phase of session initiation? Can it be kept undetected?
- tonfa 13y agoWith channel id, it would need to share the state even as laptops move across networks.