• refalo@programming.dev
    link
    fedilink
    arrow-up
    3
    ·
    5 days ago

    I wouldn’t blanket call the removal of PFS a “failure” as they put it… it does make the protocol much simpler (and hence easier to understand/audit as well) and it’s not always a necessity for every single person’s threat model… which is an important phrase the article doesn’t even mention.

    IMO arguing about security or privacy without both people first defining their threat models… is like claiming apples are objectively better than bananas in every way.