3 ms·
The ephemeral session keys should protect against the MITM attacker getting anything but another encrypted stream of data, right?
by leef 13y ago
The ephemeral session keys should protect against the MITM attacker getting anything but another encrypted stream of data, right?
- jedbrown 13y agoNo, MITM works by spoofing identity. Certificate pinning is what can protect you from a MITM with the ability to sign certificates that say "google". Ephemeral keys only protect the session from being decrypted by a passive adversary.
- biot 13y agoOnly if you can prove that your ephemeral session keys were negotiated with the intended destination. With a MITM, here's what you think is happening: Encrypt Outbound ==> Decrypt Inbound at Source at Destination Decrypt Inbound <== Encrypt Outbound at Source at Destination The ==> and <== indicate secure steps. How do you know your secure connection isn't with the Attacker who then transparently proxies all communications back and forth using a separately negotiated secure connection with the Destination? To you it looks secure, but in reality what happens is this: Encrypt Outbound ==> Decrypt/Intercept --> Re-Encrypt ==> Decrypt Inbound at Source at Attacker at Attacker at Destination Decrypt Inbound <== Re-Encrypt <-- Decrypt/Intercept <== Encrypt Outbound at Source at Attacker at Attacker at Destination The --> and <-- indicate nonsecure steps. This happens through all phases from SSL handshake to streaming of data and, if the Attacker is able to use a certificate that you trust, the interception will generally go unnoticed.