3 ms·
This article seems to be mostly FUD. Per-session, ephemeral SSL keys are available and are used by at least Google [1], CloudFlare[2], and others. No keys are
by leef 13y ago
This article seems to be mostly FUD. Per-session, ephemeral SSL keys are available and are used by at least Google [1], CloudFlare[2], and others.
No keys are stored, no keys can be given to the NSA.
1 - https://www.imperialviolet.org/2011/11/22/forwardsecret.html https://www.imperialviolet.org/2011/11/22/forwardsecret.html
2 - http://blog.cloudflare.com/cloudflare-prism-secure-ciphers http://blog.cloudflare.com/cloudflare-prism-secure-ciphers
- dlitz 13y agoThat's only true in a pure eavesdropping scenario. The keys would still allow MITM attacks.
- mpyne 13y agoExcept for cert pinning. I think moxie is working on a general form of that right now.
- dlitz 13y agoCert pinning doesn't solve that problem. Cert pinning solves the problem of a compromised CA signing false certificates. If an attacker has the private key of the endpoint, cert pinning will do nothing.
- mpyne 13y agoI.e. the attacker completely simulates the desired endpoint since they have the priv key, DNS and all? I think that makes sense indeed.