Reason.com - Free Minds and Free Markets
Reason logo Reason logo
  • Latest
  • Magazine
    • Current Issue
    • Archives
    • Subscribe
    • Crossword
  • Video
  • Podcasts
    • All Shows
    • The Reason Roundtable
    • The Reason Interview With Nick Gillespie
    • The Soho Forum Debates
    • Just Asking Questions
    • The Best of Reason Magazine
    • Why We Can't Have Nice Things
  • Volokh
  • Newsletters
  • Donate
    • Donate Online
    • Donate Crypto
    • Ways To Give To Reason Foundation
    • Torchbearer Society
    • Planned Giving
  • Subscribe
    • Reason Plus Subscription
    • Print Subscription
    • Gift Subscriptions
    • Subscriber Support

Login Form

Create new account
Forgot password

Civil Liberties

Twitter Takes Steps To Frustrate NSA, Other Government Snoops

J.D. Tuccille | 11.25.2013 10:51 AM

Share on FacebookShare on XShare on RedditShare by emailPrint friendly versionCopy page URL
Media Contact & Reprint Requests
Twitter
Twitter

Twitter announced Friday that it's joining other tech companies in implementing "perfect forward secrecy." While many online services already encrypt user comunications and other data, this form of encryption ensures that snoops—we're looking at you, National Security Agency—who break through the encryption get access to only a snippet of data, rather than everything belonging to a user. Even where a warrant is involved, perfect forward secrecy has the potential to limit intrusions, rather than acting as an open-ended skeleton key.

From Twitter's Jacob Hoffman-Andrews:

As part of our continuing effort to keep our users' information as secure as possible, we're happy to announce that we recently enabled forward secrecy for traffic on twitter.com, api.twitter.com, and mobile.twitter.com. On top of the usual confidentiality and integrity properties of HTTPS, forward secrecy adds a new property. If an adversary is currently recording all Twitter users' encrypted traffic, and they later crack or steal Twitter's private keys, they should not be able to use those keys to decrypt the recorded traffic.

The Electronic Frontier Foundation's Parker Higgins describes how perfect forward secrecy works:

How can perfect forward secrecy help protect user privacy against that kind of threat? In order to understand that, it's helpful to have a basic idea of how HTTPS works in general. Every Web server that uses HTTPS has its own secret key that it uses to encrypt data that it sends to users. Specifically, it uses that secret key to generate a new "session key" that only the server and the browser know. Without that secret key, the traffic traveling back and forth between the user and the server is incomprehensible, to the NSA and to any other eavesdroppers.

But imagine that some of that incomprehensible data is being recorded anyway—as leaked NSA documents confirm the agency is doing. An eavesdropper who gets the secret key at any time in the future—even years later—can use it to decrypt all of the stored data! That means that the encrypted data, once stored, is only as secure as the secret key, which may be vulnerable to compromised server security or disclosure by the service provider.

That's where perfect forward secrecy comes in. When an encrypted connection uses perfect forward secrecy, that means that the session keys the server generates are truly ephemeral, and even somebody with access to the secret key can't later derive the relevant session key that would allow her to decrypt any particular HTTPS session. So intercepted encrypted data is protected from prying eyes long into the future, even if the website's secret key is later compromised.

Facebook also plans to implement perfect forward secrecy, and Google has had it in place since 2011. Google points out that "not even the server operator will be able to retroactively decrypt HTTPS sessions," meaning that companies that implement the security can't turn users' lives into open books, no matter the pressure they face.

As fuck-yous to the surveillance state go, this is both welcome, and effective.

The Rattler is a weekly newsletter from J.D. Tuccille. If you care about government overreach and tangible threats to everyday liberty, this is for you.

This field is for validation purposes and should be left unchanged.

NEXT: Obama: I'm "Not a Particularly Ideological Person"

J.D. Tuccille is a contributing editor at Reason.

Civil LibertiesScience & TechnologyTwitterSurveillanceCybersecurity
Share on FacebookShare on XShare on RedditShare by emailPrint friendly versionCopy page URL
Media Contact & Reprint Requests

Show Comments (26)

Latest

James Comey's Deleted '86 47' Instagram Post Is Obviously Protected by the First Amendment

Billy Binion | 5.16.2025 4:48 PM

New Montana Law Blocks the State From Buying Private Data To Skirt the Fourth Amendment

Joe Lancaster | 5.16.2025 4:05 PM

Trump's Tariffs Are Sapping Small Business Optimism

Autumn Billings | 5.16.2025 12:00 PM

Andor Is a Star Wars Show About the Brutality of Bureaucracy

Peter Suderman | 5.16.2025 10:10 AM

Quality Seeds

Liz Wolfe | 5.16.2025 9:31 AM

Recommended

  • About
  • Browse Topics
  • Events
  • Staff
  • Jobs
  • Donate
  • Advertise
  • Subscribe
  • Contact
  • Media
  • Shop
  • Amazon
Reason Facebook@reason on XReason InstagramReason TikTokReason YoutubeApple PodcastsReason on FlipboardReason RSS

© 2024 Reason Foundation | Accessibility | Privacy Policy | Terms Of Use

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

r

Do you care about free minds and free markets? Sign up to get the biggest stories from Reason in your inbox every afternoon.

This field is for validation purposes and should be left unchanged.

This modal will close in 10

Reason Plus

Special Offer!

  • Full digital edition access
  • No ads
  • Commenting privileges

Just $25 per year

Join Today!