This is something that striked me as missing in the Lavabit key warrant discussion: was Forward Secrecy merely an option on the server before the shutdown, or was it enforced on all connections, regardless of client support?
If not all connections used it, FBI / NSA are probably now in the position to decrypt earlier recordings of user sessions, thus recovering the passwords, email contents etc...
From reading the ssllabs report, it looks like even with the current setup, sessions by IE and Safari (also Android?) users can be recovered once the new key is obtained via court order.
If not all connections used it, FBI / NSA are probably now in the position to decrypt earlier recordings of user sessions, thus recovering the passwords, email contents etc...
From reading the ssllabs report, it looks like even with the current setup, sessions by IE and Safari (also Android?) users can be recovered once the new key is obtained via court order.