@soatok @risottobias @dalias @khm @ambiguous_yelp @sammi @joelanman
Another point worth noting is that the way they implemented PFS in signal's ratchet, it's not like you could compromise a session by breaking a single key exchange. Instead, in a hypothetical store-now-decrypt-later attack you would have to have a (gapless!) history of all traffic in either direction between two devices since they established contact, and you'd have to crack thousands of key exchanges.