Does IVPN offer Perfect Forward Secrecy (PFS)?

    Yes, our OpenVPN servers are configured to automatically generate new encryption keys every hour. If an adversary was able to crack the encryption key, they would only be able to decrypt the traffic captures since the last key rotation.

    To give you some idea of the requirements to brute force an AES 256 bit key, 50 supercomputers that could check a billion billion (10^18) AES keys per second. If such a device could ever be made it would, in theory, require about 3 × 10^51 years to exhaust the 256-bit key space.

    Related Articles

    Still have questions?

    Get in touch and we'll get back to you in a few hours.

    Contact support

    Interested in privacy?

    Read our latest privacy news and keep up-to-date on IVPN services.

    Visit IVPN Blog
    Spotted a mistake or have an idea on how to improve this page?
    Suggest an edit on GitHub.