> Yes you are wrong :D If NSA is not actively man-in-the-middling you, Perfect forward secrecy still works.
OK, I guess I was reading too much into the (not very enlightening) definition of PFS on Wikipedia and too little of the actual implementation based on Diffie-Hellman, which has the desired properties.
The question that arises is: how feasible is a MITM attack on this phase of session initiation? Can it be kept undetected?
ECDHE has been in Openssl since version 1.0.0 so its out there just not used.
Btw. Is there any addon for Firefox that shows the “encrypted communication” details like google does?