Conversation

Key exchange is what needs to be improved in the short term because that's what has to hold up to future attacks. It's already almost entirely ECDHE with ed25519 or in some cases still P-256. Only legacy setups still use RSA for key exchange because it lacks forward secrecy.
1
1
TLS 1.3 only has ECDHE key exchange. DHE and RSA key exchange are gone. It still supports RSA for server / client authentication but that's not as important and doesn't need to be secure into the future. It's a legacy feature since it isn't an option for key exchange anymore.
1
Show more replies