Hacker News new | past | comments | ask | show | jobs | submit
Can a theoretical strong enough quantum computer break PFS?
QC breaks perfect forward secrecy schemes using non-PQC algorithms, same as for non-PFS. PFS schemes typically use single-use ephemeral DH/ECDH key pairs for symmetric key exchange, separate from the long-term signing keys for authentication.
If you store a whole session of traffic from today you can break the key exchange with a quantum computer in the future.

AES probably can't be broken but that's irrelevant because in this scenario you have the key in plaintext from the key exchange