That being said, tptacek thinks we are wrong, and he is a subject matter expert, so I am not sure.
So... If I understand everything correctly, it should be impossible to decrypt passively captured HTTPS traffic to/from google.com.
http://www.quora.com/SSL-Secure-Sockets-Layer/Is-it-ever-pos...
Could someone more knowledgeable confirm this?
> openssl s_client -connect google.com:443 RC4-SHA > openssl s_client -connect dropbox.com:443 DHE-RSA-AES256-SHA
Again, this is usually done for speed, but all of the companies on the list are using "fast" SSL/TLS ciphers rather than more secure ones.
I open google.com in Chrome, click on lockpad icon, go to the second tab, and it says: Key exchange method: ECDHE_ECDSA
Some googling turns up that: "ECDHE-ECDSA provide perfect forward secrecy" http://nmav.gnutls.org/2011/12/price-to-pay-for-perfect-forw...
Ian Gallager: > so if you have the private key, you can decrypt that key, and then use it to decrypt the bulk-encrypted data.
Like he says, if you have the key, wireshark can decrypt the data trivially.
If you have the CA master keys, then the only thing you can do is perform a MITM attack, but not silently decrypt the raw data. A MITM attack would eventually get detected.
How does that make a difference when you have the Diffie-Hellman key? We are saying they have the Diffie-Hellman keys, not the signing keys, nor the block cipher key that is exchanged. They have the only key that matters.
But I am still lost on how it would be detectable? From Google's end, some client just disconnected. From the client's end, the internet just got a tiny bit more latency.
But while the signing key may allow them to impersonate Google in some circumstances, it doesn't really help decrypting passively recorded TLS traffic to the real Google. For that, they would need to break the ECDH key exchange, and if Google uses reasonable elliptic curve parameters, that's presumably much harder than factoring a 1024-bit RSA modulus, at least with known cryptanalytic techniques.
Really, I would think it would be easy for the NSA, etc to get an operative inside Google, FB etc and steal these. Intelligence organizations are very good at this after all..
One possibility is to actually compute discrete logarithms.
Does anyone know what elliptic curve parameters Gmail uses for key exchange? If the parameters are large, it is not feasible to break discrete logs using known methods, but while I'm usually wary of claims that the NSA is miles ahead of the academic research community, I could perhaps believe they have faster algorithms for e.g. some NIST curves.
http://googleonlinesecurity.blogspot.com.au/2011/11/protecti...
Could you link to tptacek's comments you're referring to?
https://news.ycombinator.com/item?id=5842915
I was being a bit devious. I am just so tired of tptacek dismissing stuff I say with asinine arguments and then watching my comment get downvoted to hell.
These are all moderately 'cheap' steps if you believe you're being compromised in this manner.
Beam splitters are not enough, they would need something to interpret this traffic.
Something is missing here.
We store only parity of data in one data center, and some in another on a different continent. Any data intercepted or lost does not damage the integrity of the whole, plus this makes ISP can not discriminate raw binary data.
[1] http://en.wikipedia.org/wiki/Secret_sharing, invented by Adi Shamir, the S of RSA