3 ms·
In order to provide any forward secrecy, the PFS keys are generated randomly for each session. They are not derived from the certificate holder's RSA keys. A s
by phlo 13y ago
In order to provide any forward secrecy, the PFS keys are generated randomly for each session. They are not derived from the certificate holder's RSA keys.
A snooping agency holding the private key of, say, Google would still need to intercept each connection and act as a man in the middle. Simply knowing the RSA key (either beforehand or afterwards) is not enough to decrypt PFS sessions.
*edit: Google would still be able to collect and hand over all session keys ever used to communicate with them. The NSA might then use those session keys to decrypt any corresponding session.