▲ | arkadiyt 2 months ago | |||||||||||||||||||||||||||||||
> does a 4096 not give you more security against passive capture and future decrypting? If the server was using a key exchange that did not support forward secrecy then yes. But:
^ they're using ECDHE (elliptic curve diffie hellman), which is providing forward secrecy. | ||||||||||||||||||||||||||||||||
▲ | nothrabannosir 2 months ago | parent [-] | |||||||||||||||||||||||||||||||
I thought FS only protected other sessions from leak of your current session key. How does it protect against passive recording of the session and later attacking of the recorded session in the future? | ||||||||||||||||||||||||||||||||
|