Hacker News new | ask | show | jobs
by hrjet 4630 days ago
Well, the browsers could disable non PFS ciphers by default. When a site doesn't match any PFS cipher list, show a pop-up with a way to add an exception for the site.

Much more graceful than a complete switch-over and doesn't require co-ordination from other vendors.