4 ms·
The majority of SSL implementations do not support perfect forward secrecy in any form. The bare SSL standard itself has no room for it. You need at least TLS 1
by rabite 5y ago
The majority of SSL implementations do not support perfect forward secrecy in any form. The bare SSL standard itself has no room for it. You need at least TLS 1.3 to get any shot at PFS -- and then again most SSL standards allow for negotiation of at least slightly older protocols.
Plain SSL is also broken by NAT transversal. There's a chat protocol that does do something very similar to what you're asking: Ricochet Refresh. Ricochet Refresh spawns a Tor hidden service and provides an API via it and no text logging. Tor's transit mechanism always has confidentiality, authenticity, deniability, and perfect forward secrecy. https://www.ricochetrefresh.net/ https://www.ricochetrefresh.net/
Unfortunately there are no mobile clients for this.