Glossary

What is forward secrecy?

Forward secrecy, also called perfect forward secrecy (PFS), is a property of encryption protocols where each session uses fresh, temporary keys that are deleted afterward. If a long-term key is stolen later, past conversations stay private, because the keys that actually protected them no longer exist.

Also called: perfect forward secrecy, PFS

Updated September 2026. Sources are numbered and listed at the end.

How forward secrecy works

Compare two ways a server and your browser can agree on a session key.

Without forward secrecyWith forward secrecy
How the session key is setYour browser encrypts it to the server’s long-term RSA keyBoth sides generate throwaway key pairs and run a fresh key exchange
What the long-term key doesUnlocks every session keyOnly proves the server’s identity
If the long-term key leaks laterEvery recorded session can be decryptedRecorded sessions stay sealed

Messaging apps go further with a ratchet: a new key for every message, derived in a way that can’t be run backward. Signal’s Double Ratchet is the best-known design.1

Why it matters, and what it can’t do

Keys get stolen: through server breaches, bugs, or legal orders. Forward secrecy limits the damage to the present instead of the whole history.

It also changes what a single breach is worth. Without it, one stolen server key unlocks years of recorded traffic, which makes recording traffic worthwhile on the chance a key leaks someday. With it, an attacker has to break into each session while it is happening.

It does not protect against a broken algorithm. A future quantum computer wouldn’t need a stolen key. It could solve the recorded elliptic-curve exchange directly and recover each session key, one by one. That’s why harvest now, decrypt later still works against forward-secret protocols that use classical math, and why new designs keep forward secrecy while swapping in post-quantum algorithms. Signal’s Sparse Post-Quantum Ratchet, added in October 2025, is built to provide forward secrecy in a quantum-safe way.2

Where you’ll see it

  • TLS 1.3 (every modern HTTPS connection): the standard removed static RSA and Diffie-Hellman key exchange, so all its public-key key exchanges provide forward secrecy.3
  • WireGuard performs a new handshake every couple of minutes, providing rotating keys for perfect forward secrecy.4
  • Messaging apps like Signal ratchet keys per message. Our guide Is Signal safer than email? compares the two.

Forward secrecy in Secria

Secria Mail encrypts each email with its own unique ephemeral keys, using salt-based derivation, so compromising one message key doesn’t affect your other messages. Secria VPN runs on WireGuard, which rotates session keys every few minutes, and adds a fresh ML-KEM-1024 protected key on every connection. More on Secria Mail and Secria VPN.

Sources

  1. Signal, The Double Ratchet algorithm.
  2. Signal, Signal protocol and post-quantum ratchets (October 2025).
  3. IETF, RFC 8446: The Transport Layer Security (TLS) Protocol Version 1.3, section 1.2 (August 2018).
  4. WireGuard, Protocol and cryptography.

Checked September 2026. Secria facts are from our Mail and VPN pages and the whitepaper.

Questions about forward secrecy

Is forward secrecy the same as perfect forward secrecy?+

Yes. They name the same property. “Perfect” is the older term; many cryptographers now drop it because no system is perfect.

Does TLS 1.3 always have forward secrecy?+

For full handshakes, yes: RFC 8446 removed the key exchanges that lacked it. Some session resumption modes and early data trade it away for speed.

Does forward secrecy protect against quantum computers?+

Not by itself. A quantum computer can solve a recorded classical key exchange directly. You need forward secrecy plus a post-quantum key exchange such as ML-KEM.

What is post-compromise security?+

The reverse direction: after a key leaks, the protocol heals itself so future messages become private again. Ratcheting protocols like Signal’s aim to provide both.

Email that’s ready for what comes next. Post-quantum encryption on every plan, free included.