False, one can't passively mitm SSL when perfect-forward-secrecy is used. I just checked, and google seems to be using it.
http://www.quora.com/SSL-Secure-Sockets-Layer/Is-it-ever-pos...
False, one can't passively mitm SSL when perfect-forward-secrecy is used. I just checked, and google seems to be using it.
http://www.quora.com/SSL-Secure-Sockets-Layer/Is-it-ever-pos...
But yes, if PFS key exchange is used in TLS then having the private key alone would not help with decrypting previously gathered packet data. In that case the only thing I can think of for NSA to read the data is if they successfully created (in secret of course) a practical quantum computer which then renders RSA and DHE (anything that relies on integer factorization or discrete logs for that matter) completely broken.
"In addition in Chromium 13, only a very small subset of CAs have the authority to vouch for Gmail (and the Google Accounts login page). This can protect against recent incidents where a CA has its authority abused, and generally protects against the proliferation of signing authority."
(disclaimer: I work for Chrome but not on these features.)
Google uses Diffie–Hellman key exchange which provides perfect forward secrecy.
So... If I understand everything correctly, it should be impossible to decrypt passively captured SSL-encrypted communication to/from google.com.
Edit: replying to the poster below, it doesn't have to be a passive attack, and I'm not sure what you mean about checksums. The scenario above would look exactly like normal Internet traffic. You're not mutating packets, you're sending entirely new ones.
Me in Europe ------200 ms------- MITM magic --1 ms-- Google
For the attacker not to introduce huge extra latency, it would need to complete the handshake with Google almost instantly. Someone would eventually notice instantaneous TLS handshakes.
Also 2 separate TLS connections would contribute to bufferbloat pretty badly, and someone would also eventually investigate that.
then there are 2 endpoints that are decrypted separately
"I realized that the U.S. government loves the "PRISM" acronym. There are literally dozens of projects and applications named PRISM at the state and federal level, many with delightfully goofy logos."
http://waxy.org/2013/06/these_arent_the_prisms_youre_looking...;