-
Just read "Imperfect Forward Secrecy: How Diffie-Hellman Fails in Practice" (weakdh.org/imperfect-forward-secrecy-ccs15.pdf) again. This truly is an excellent paper and stands very well 4 years later. No redundant sentence, and a lot of content in really concise but understandable form. Students: read!