rdroms / draft-green-tls-static-dh-in-tls13

Work area for Internet Draft draft-green-tls-static-dh-in-tls13
0 stars 0 forks source link

Edit to Security Considerations #21

Closed rdroms closed 7 years ago

rdroms commented 7 years ago

From Tim Polk:

OLD

  1. The shift from fully-ephemeral ECHDE to partially static ECDHE affects the security properties offered by the TLS 1.3 handshake by eliminating the Forward Secrecy property provided by the server. If a server is compromised and the private key is stolen, then an attacker who observes any TLS handshake (even one that occurred prior to the compromise) will be able to recover traffic encryption keys and will be able to decrypt traffic. NEW
  2. The shift from fully-ephemeral (EC)DHE to use of static (EC)DHE server keys affects the security properties offered by the TLS 1.3 handshake by eliminating the Forward Secrecy property. If a server is compromised and the private key is stolen, then an attacker who observes any TLS handshake (even one that occurred prior to the compromise) performed with this static (EC)DHE key pair will be able to recover session encryption keys and will be able to decrypt traffic.
rdroms commented 7 years ago

Change made and update pushed.