Another approach with proposed scheme: receiver can punctures decryption key regularly with known time-period. So sender can manages PFS himself: send message with "best before" life-time (while receiver still viable and honest of course). This can be useful in some cases.
_______________________________________________ Messaging mailing list Messaging@moderncrypto.org https://moderncrypto.org/mailman/listinfo/messaging