After the new revelations every site who's using SSL should be using Perfect Forward Secrecy with it, too. Right now, only a few known companies like Google (only for the search engine probably), DuckDuckGo, and Ixquick/Startpage are using it.<p>Considering NSA is collecting as many keys as possible, let's at least make their job exponentially harder by encrypting every session and every message with a new key with PFS. It's the <i>least</i> these companies can do, if they're serious about their users' privacy.<p>Also, as Bruce is saying - use 3072 bit or even 4096 bit RSA keys (or better alternatives) and AES-256 as soon as possible (hopefully within a year).