Perfect Forward Secrecy

Also known as: PFS, forward secrecy

A property of key exchange, obtained through ephemeral Diffie-Hellman, in which every session derives a key that is discarded once the session ends. Should a server's long-term private key later be stolen or compelled, previously recorded traffic still cannot be decrypted, because that key never encrypted it. TLS 1.3 requires the property; under TLS 1.2 it depends on the negotiated cipher suite.

Browse all terms in Privacy & Security, or see the full Usenet glossary.

Put it into practice with the world's best usenet service