|
|
|
|
|
by tptacek
3184 days ago
|
|
The 'P' in 'PFS' has always stretched the truth, which is why a lot of practitioners elide it. Even if you never rotate STEKs and never reset systems to get a new STEK accidentally, the DH handshake is still providing forward secrecy value for clients who don't do session tickets. |
|