We use cookies to understand how the site is used and to improve it. You can accept them, or carry on with them switched off.
Also known as: PFS, forward secrecy
A property of key exchange, obtained through ephemeral Diffie-Hellman, in which every session derives a key that is discarded once the session ends. Should a server's long-term private key later be stolen or compelled, previously recorded traffic still cannot be decrypted, because that key never encrypted it. TLS 1.3 requires the property; under TLS 1.2 it depends on the negotiated cipher suite.
Browse all terms in Privacy & Security, or see the full Usenet glossary.