▲ | arkadiyt 2 months ago | |||||||
If using a non-FS key exchange (like RSA) then the value that the session key is derived from (the pre-master secret) is sent over the wire encrypted using the server's public key. If that session is recorded and in the future the server's private key is obtained, it can be used to decrypt the pre-master secret, derive the session key, and decrypt the entire session. If on the other hand you use a FS key exchange (like ECDHE), and the session is recorded, and the server's private key is obtained, the session key cannot be recovered (that's a property of ECDHE or any forward-secure key exchange), and none of the traffic is decryptable. | ||||||||
▲ | nothrabannosir 2 months ago | parent | next [-] | |||||||
Thanks I think I understand better now! | ||||||||
▲ | dingaling 2 months ago | parent | prev [-] | |||||||
> the session key cannot be recovered Of course it can, but only for that specific session. | ||||||||
|