Does the chunked streaming protocol have future secrecy? #674
-
|
Does age employ ratcheting of the symmetric key for its chunked stream format? Suppose we have |
Beta Was this translation helpful? Give feedback.
Replies: 1 comment 1 reply
-
|
The STREAM key remains the same throughout the stream, with only the non-secret nonce changing, so there is no future secrecy. age is made for encrypting files, not long-lived streams. Even many TLS implementations don't provide future secrecy within a single connection (despite rekey being supported by the protocol). For this, you might want to use Noise with Rekey or TLS with forced KeyUpdates. |
Beta Was this translation helpful? Give feedback.
The STREAM key remains the same throughout the stream, with only the non-secret nonce changing, so there is no future secrecy.
age is made for encrypting files, not long-lived streams. Even many TLS implementations don't provide future secrecy within a single connection (despite rekey being supported by the protocol). For this, you might want to use Noise with Rekey or TLS with forced KeyUpdates.