4 ms·
While this initially struck me as black magic, I think I've figured out how it's possible: I'm guessing that you somehow take advantage of perfect forward secr
by sillysaurus2 13y ago
While this initially struck me as black magic, I think I've figured out how it's possible: I'm guessing that you somehow take advantage of perfect forward secrecy. PFS works by constantly "cycling" the encryption key in memory so that each packet is signed by the next iteration of the key, and the previous key is erased. Since SSL has support for PFS, I'm guessing it works like this: You have the website owner store the cert on their servers. Then you issue a request to the website owner, asking them to transmit their initial private key to you. (This would be the most vulnerable part of this new setup, but it could be done reasonably securely.)
Once you receive their private key, you use it to generate HTTPS traffic on the website owner's behalf. And since you're using PFS, then it doesn't matter if anyone obtains that key: every packet you send will cause PFS to cycle the current key (generating a new one) and erase the previous key. Really clever!
It's a little worrisome that CloudFlare will be issuing automated requests to website owners asking them for their initial private key (I'm absolutely certain you're going to do that, because otherwise your proposal is impossible) so I'll be curious to find out what steps you'll take to make it very difficult for an attacker to impersonate CloudFlare and request it, or MITM you and intercept it. But, this is wonderful progress.
Ultimately, that will be the logical response: to MITM you and snag every private key the moment you request it. But at least it'd no longer be possible for a court to demand you give up a static, unchanging key, which is a huge step forward. Plus it might take an unreasonable amount of resources to set up such an MITM attack... but it may become a realistic concern once CloudFlare begins powering most of the internet (which seems likely).
And I just want to say: thank you for working so hard on this problem!
- nitrogen 13y agoIf I understand PFS and your idea correctly, the master site wouldn't need to send its RSA or ECDSA private key to CloudFlare, just an ephemeral connection-specific key once it has been negotiated with the master. I haven't thought enough yet to know if that provides additional security, or whether it cancels out the benefit of CloudFlare's caching.