TLS 1.3 - Decryption Misconceptions - The Ramblings of A Security Guy
TLS 1.3 - Decryption Misconceptions - The Ramblings of A Security Guy
> $ cd /home/
About
Posts
7 minutes
Why would you want to decrypt TLS in the first place? There are
valid reasons for this and they have been briefly looked at in one
of my previous posts which you can find here. We won’t be going
over that again here.
https://mikeguy.co.uk/posts/2018/11/tls-1.3-decryption-misconceptions/ 1/8
10/25/22, 6:16 PM TLS 1.3 – Decryption Misconceptions :: The Ramblings of a Security Guy
1) RSA-based key-exchange
https://mikeguy.co.uk/posts/2018/11/tls-1.3-decryption-misconceptions/ 2/8
10/25/22, 6:16 PM TLS 1.3 – Decryption Misconceptions :: The Ramblings of a Security Guy
> $ cd /home/
About
Posts
https://mikeguy.co.uk/posts/2018/11/tls-1.3-decryption-misconceptions/ 3/8
10/25/22, 6:16 PM TLS 1.3 – Decryption Misconceptions :: The Ramblings of a Security Guy
https://mikeguy.co.uk/posts/2018/11/tls-1.3-decryption-misconceptions/ 4/8
10/25/22, 6:16 PM TLS 1.3 – Decryption Misconceptions :: The Ramblings of a Security Guy
> $ cd /home/
About
Posts
https://mikeguy.co.uk/posts/2018/11/tls-1.3-decryption-misconceptions/ 5/8
10/25/22, 6:16 PM TLS 1.3 – Decryption Misconceptions :: The Ramblings of a Security Guy
What this all means, is that even with a copy of the private key
> $ cd /home/
an attacker couldn’t go and decrypt data that he had previously
captured. Much more secure.
About
Lots. But the most notable things for that which we are
discussing here are:
As you can probably tell, a lot of the changes in TLS 1.3 are
around removing old, obsolete settings and improving privacy. By
encrypting the certificate and optionally the SNI, it provides end
users with more privacy from potential nosey
organisations/individuals in the middle!
https://mikeguy.co.uk/posts/2018/11/tls-1.3-decryption-misconceptions/ 7/8
10/25/22, 6:16 PM TLS 1.3 – Decryption Misconceptions :: The Ramblings of a Security Guy
Summary
> $ cd /home/
Hopefully this clarifies the situation around TLS 1.3 decryption a
bit. It isn’t entirely clear where the industry will go with it yet and About
how they will address the challenges – but time will tell! Posts
1486 Words
2018-11-30 00:00 +0000
© 2020
Mike Guy
CC BY-NC 4.0
Powered by Hugo
Hugo template created by rhazdon
All opinions on this site are my own and do not reflect those of my employer,
family or friends unless otherwise quoted
https://mikeguy.co.uk/posts/2018/11/tls-1.3-decryption-misconceptions/ 8/8