3 ms·
That hinges on browser support for DHE for key exchange (or some other method that provides PFS, like the elliptic curve optimized ones), which is not supported
by jd007 13y ago
That hinges on browser support for DHE for key exchange (or some other method that provides PFS, like the elliptic curve optimized ones), which is not supported on all browsers. Notably IE and older Chrome/FF, though this could've improved since last time I checked.
But yes, if PFS key exchange is used in TLS then having the private key alone would not help with decrypting previously gathered packet data. In that case the only thing I can think of for NSA to read the data is if they successfully created (in secret of course) a practical quantum computer which then renders RSA and DHE (anything that relies on integer factorization or discrete logs for that matter) completely broken.