For offline file encryption ( pgp isn’t intended for messaging).
I guess you mean "leak" as in "being copied", which relies on how good the hardware actually is at preventing this, but what if I just lose my hardware key, isn't that the same?
The Signal Protocol somewhat excessively provides forward secrecy for each and every message sent. That is sort of pointless while the messages still exist on the screen. Most people would be happy getting rid of their old messages every week or so. You could totally do that in an instant messaging system that used OpenPGP formatted messages. The reason that no one bothers is because few people want to dump their old encrypted emails. No one wants to dump their old encrypted files. Instead they take advantage of the greater security inherent in an offline encryption system and avoid getting their keys leaked in the first place.
If you really wanted to do message by message forward secrecy using a hash ratchet using OpenPGP formatted messages you could do that too. There is nothing magical about the Signal Protocol for stuff like that...
Relevant discussion:
Or if the message's recipient took a screenshot.
In other words, the point being that a man-in-the-middle attacker cannot decrypt past conversations that he recorded even if in the future he is able to determine the key?
It's kind of obvious that you cannot prevent the other party from saving the messages, but from what I understand I don't think that's what forward secrecy is even trying to do (disclaimer: I'm not a cryptographer).
Yes. Exactly. Only the transport part is protected. Contrast, say, TLS with messaging. TLS is basically an encrypted pipe. Plaintext goes in and plaintext comes out. If someone saves some of that plaintext and it gets leaked, well, that isn't your job to prevent that but you can at least provide forward secrecy. After all, people don't normally save their sensitive web pages for extended periods of time...
With messaging, saving old messages is more or less the default. When that happens the value of forward secrecy is negated. If you want your old messages to be gone, you (and your correspondent) actually have to get rid of them.
>...man-in-the-middle attacker...
Terminology quibble. I think this would be normally described as recording the encrypted messages off the wire. MITM implies than an attacker is impersonating one or more correspondents.
Well, isn't that valuable?
> With messaging, saving old messages is more or less the default. When that happens the value of forward secrecy is negated.
It's not negated because a passive attacker that records communications and then, in the (potentially far) future, somehow can obtain the key (say, by exploiting some weakness and/or brute-forcing), still cannot decrypt your past communications, regardless of whether everybody saves old messages or not.
By passive attacker, I mean someone like the NSA, your ISP, your messaging provider, the server/P2P host that relays your messages, etc.
> If you want your old messages to be gone, you (and your correspondent) actually have to get rid of them.
But that's not what forward secrecy is designed to do, is it? It's designed to prevent third parties who can record the encrypted end-to-end communication from decrypting past messages when/if they can obtain your key.
It's not designed for making old messages be gone.
> Terminology quibble. I think this would be normally described as recording the encrypted messages off the wire. MITM implies than an attacker is impersonating one or more correspondents.
Yes, sorry, I meant a "passive man-in-the-middle attacker".
If someone breaks the encryption somehow then forward secrecy is also negated. They get the encrypted material directly. Forward secrecy is only effective in messaging if the attacker does something like break into your device to get the secret key material. At that point they will also get any saved messages that are still accessible to you, in whatever way they are accessible.
Now in theory a messaging client could reencrypt old messages to something like a public key pair where the secret key material was protected by a strong passphrase. But no one does that because that would mean you would have to type in the passphrase whenever you wanted to see an old message. At that point you might as well just use encrypted email and leave everything encrypted all the time.