Perfect Forward Secrecy
Perfect Forward Secrecy
Posted Jul 25, 2013 14:02 UTC (Thu) by brunowolff (guest, #71160)In reply to: Perfect Forward Secrecy by tialaramex
Parent article: Feds put heat on Web firms for master encryption keys (CNET)
There was another article about this recently which claimed that the server gets to pick which mode to use from the common set. And that since there is a performance hit to PFS, some servers will choose non-PFS modes if they are available. So on the client side you'd need to only offer up modes that support PFS and then have a backup plan for servers that don't support any PFS modes.
