How forward secrecy works
Compare two ways a server and your browser can agree on a session key.
| Without forward secrecy | With forward secrecy | |
|---|---|---|
| How the session key is set | Your browser encrypts it to the server’s long-term RSA key | Both sides generate throwaway key pairs and run a fresh key exchange |
| What the long-term key does | Unlocks every session key | Only proves the server’s identity |
| If the long-term key leaks later | Every recorded session can be decrypted | Recorded sessions stay sealed |
Messaging apps go further with a ratchet: a new key for every message, derived in a way that can’t be run backward. Signal’s Double Ratchet is the best-known design.1
Why it matters, and what it can’t do
Keys get stolen: through server breaches, bugs, or legal orders. Forward secrecy limits the damage to the present instead of the whole history.
It also changes what a single breach is worth. Without it, one stolen server key unlocks years of recorded traffic, which makes recording traffic worthwhile on the chance a key leaks someday. With it, an attacker has to break into each session while it is happening.
It does not protect against a broken algorithm. A future quantum computer wouldn’t need a stolen key. It could solve the recorded elliptic-curve exchange directly and recover each session key, one by one. That’s why harvest now, decrypt later still works against forward-secret protocols that use classical math, and why new designs keep forward secrecy while swapping in post-quantum algorithms. Signal’s Sparse Post-Quantum Ratchet, added in October 2025, is built to provide forward secrecy in a quantum-safe way.2
Where you’ll see it
- TLS 1.3 (every modern HTTPS connection): the standard removed static RSA and Diffie-Hellman key exchange, so all its public-key key exchanges provide forward secrecy.3
- WireGuard performs a new handshake every couple of minutes, providing rotating keys for perfect forward secrecy.4
- Messaging apps like Signal ratchet keys per message. Our guide Is Signal safer than email? compares the two.
Forward secrecy in Secria
Secria Mail encrypts each email with its own unique ephemeral keys, using salt-based derivation, so compromising one message key doesn’t affect your other messages. Secria VPN runs on WireGuard, which rotates session keys every few minutes, and adds a fresh ML-KEM-1024 protected key on every connection. More on Secria Mail and Secria VPN.
Related terms
Sources
- Signal, The Double Ratchet algorithm.
- Signal, Signal protocol and post-quantum ratchets (October 2025).
- IETF, RFC 8446: The Transport Layer Security (TLS) Protocol Version 1.3, section 1.2 (August 2018).
- WireGuard, Protocol and cryptography.
Checked September 2026. Secria facts are from our Mail and VPN pages and the whitepaper.