3 ms·
I think (not an expert) that with elliptic curve Diffie-Hellman (which e.g. Google uses), even with the private key and the whole session, you still can't decry
by Robin_Message 13y ago
I think (not an expert) that with elliptic curve Diffie-Hellman (which e.g. Google uses), even with the private key and the whole session, you still can't decrypt the session (Diffie-Hellman provides a secure channel, public/private proves the server is who it says it is).
- sneak 13y agoThat is correct. These are referred to as ECDHE, or DHE for the non-ECC variant (vanilla DH). The last e is "ephemeral", referring to the lifetime of the session key. The property that this provides is known as "forward secrecy".