KotoVPN

Glossary

Perfect forward secrecy

Generating a new session key for each connection, so a future key compromise cannot decrypt past recorded traffic.

Why it matters

It defends against the realistic attack: record encrypted traffic now, obtain the key later. Without it, one key compromise retroactively exposes everything captured.

What most explanations leave out

It is standard in modern configurations rather than a differentiator, and both WireGuard and correctly configured OpenVPN provide it. Its absence would be a serious finding; its presence is not a selling point.

Related terms

AES-256

A symmetric encryption cipher with a 256-bit key, standard in OpenVPN and IKEv2 configurations.

VPN protocol

The set of rules governing how the tunnel is established and how data is encrypted inside it.

Terms are defined here because they appear in our scoring rubric or in provider reviews, not to fill a glossary.