Open cardosec

Case 7ED117 · Cryptography · L2 Practitioner

Forward Secrecy

Practise as: Explain it · Interview

Interview questionWhat is forward secrecy and why does it matter if a server private key is stolen?

  1. 01 What is it?
  2. 02 How is it abused?
  3. 03 How do you stop it?
What a strong answer covers

Try it out loud first. Then check yourself:

  1. Forward secrecy means compromise of long-term keys does not reveal past session keys.
  2. Achieved with ephemeral DH/ECDHE: a fresh key pair per session, discarded after key derivation.
  3. With static RSA key exchange, a stolen private key decrypts every recorded past session (harvest now, decrypt later).
  4. Long-lived TLS session ticket keys can undermine FS; rotate ticket keys frequently.

If the interviewer pushes back

  • How does the Signal Double Ratchet provide both forward secrecy and post-compromise security?

cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.