Forward Secrecy and the Double Ratchet, Explained Clearly
Forward secrecy and post-compromise security explained: how the Double Ratchet gives every message its own key, and how VOIDEX adds post-quantum re-keying.
End-to-end encryption answers one question: can anyone in the middle read this message? It says less about a second question that matters just as much: what happens if a key is ever stolen?
The answer to that second question is where modern messaging protocols quietly earn their reputation. Two properties, forward secrecy and post-compromise security, decide whether one bad day exposes a single message or an entire relationship. This article explains both in plain language, credits the design that made them mainstream, and shows how VOIDEX Messenger applies them with post-quantum re-keying so that every message has its own key.
The problem with one key forever
Imagine a conversation protected by a single long-term key. It works perfectly, until the day that key leaks. A compromised phone, a malicious backup, a subpoenaed server that kept copies of old traffic. Whoever holds the key can now decrypt everything: yesterday, last month, the first message ever sent.
Worse, they can keep reading. Every future message is locked with the same key they already have.
A single key forever turns one failure into total failure, in both directions of time. Good protocols are designed so that failures stay small.
Forward secrecy: the past stays sealed
Forward secrecy means that if an attacker steals your keys today, they still cannot decrypt messages you sent and received before the theft.
The trick is to keep changing keys and to destroy the old ones. If the key for last Tuesday's message no longer exists anywhere, there is nothing to steal. Even an adversary who recorded the ciphertext at the time, and there are many who do, is left holding locked boxes with no key in the world that opens them.
This matters more than it first appears. Intelligence agencies and criminal groups alike collect encrypted traffic in bulk and store it, betting that a key will surface later. The same logic drives the quantum threat described in harvest now, decrypt later. Forward secrecy is the discipline of making sure that when a key does surface, it unlocks as little as possible.
Post-compromise security: the future heals
Forward secrecy protects the past. Post-compromise security, sometimes called future secrecy or self-healing, protects the future.
Suppose an attacker briefly copies the secret state from your phone and then loses access. With post-compromise security, the conversation recovers on its own: after a few new messages are exchanged, fresh secret material is mixed in that the attacker never saw, and they are locked out again.
Together the two properties shrink the damage of any breach to a narrow window of time, rather than letting it spread backwards and forwards through your entire history.
The Double Ratchet
The design that brought both properties to billions of people is the Double Ratchet algorithm, created by Trevor Perrin and Moxie Marlinspike for what became the Signal Protocol. Signal published the Double Ratchet specification openly, and it has since been adopted, studied and built upon across the industry. It is one of the most important pieces of public-interest cryptography of the last decade, and credit belongs to its authors.
The name describes how it works. A ratchet is a mechanism that turns only one way. The Double Ratchet has two of them working together.
The symmetric ratchet: a new key for every message
Each side of a conversation keeps a chain of keys. To send a message, your device derives a fresh message key from the current chain, uses it once, and then moves the chain forward using a one-way function. The old chain value is deleted.
Because the function only runs forward, you cannot work backwards from today's chain to yesterday's keys. That is forward secrecy at the level of individual messages. Every message is encrypted under its own key, and that key is discarded after use.
The Diffie-Hellman ratchet: fresh secrets from both sides
The symmetric ratchet alone cannot heal from a compromise: if an attacker copies the current chain, they can follow it forward indefinitely. So the second ratchet regularly injects new randomness.
As messages go back and forth, each side generates new key pairs and performs a fresh Diffie-Hellman exchange, then mixes the result into the root of both chains. An attacker who stole yesterday's state does not have the new private keys, so once a round trip happens, the chains they were following are replaced with ones they cannot compute. That is post-compromise security.
Out-of-order and lost messages are handled by keeping a small, bounded set of skipped keys, so real-world networks with delays do not break the conversation.
The quantum complication
Classic Double Ratchet implementations use elliptic-curve Diffie-Hellman, such as X25519. It is fast and trusted today, but a sufficiently large quantum computer running Shor's algorithm would break it. Recent research has pushed estimates of the resources needed for such attacks down sharply, as covered in Q-Day in 2026.
The response across the industry has been to add post-quantum algorithms alongside the classical ones. Signal introduced PQXDH in 2023 to protect the start of a conversation, and in October 2025 announced SPQR, a post-quantum ratchet using ML-KEM-768 that it describes as a Triple Ratchet. Apple's iMessage added post-quantum re-keying with PQ3 in 2024. These are serious, well-engineered steps.
The shared idea is hybrid security: combine a classical exchange with a post-quantum key encapsulation mechanism such as ML-KEM, standardised by NIST in FIPS 203, so that an attacker would need to break both. More on that in hybrid post-quantum encryption.
How VOIDEX Messenger does it
In VOIDEX Messenger, direct messages begin with a hybrid post-quantum key agreement, X25519 combined with ML-KEM-768, in a PQXDH-style handshake. From there, messages run on a double ratchet with post-quantum re-keying.
In practice that means:
- Every message has its own key, derived once, used once and discarded, so a stolen key cannot open the past.
- The conversation heals after a compromise, because fresh secret material, including post-quantum material, keeps being mixed in.
- Identities are signed with hybrid signatures, Ed25519 together with ML-DSA-65, so the question of who you are talking to is also protected against future quantum attacks.
- Keys are checked against a public log. Every device key change is appended to an append-only Merkle log, and VOIDEX clients refuse keys that are not in it. See key transparency.
Groups and private channels use MLS, the IETF standard in RFC 9420, which is designed to provide forward secrecy and post-compromise security for many members at once.
The cryptographic core is open source at github.com/voidexbycnota/voidex-crypto, so these claims can be read in code rather than taken on trust.
An honest exception: your message history
There is one place where VOIDEX deliberately chooses something different, and it is better to say so plainly.
Pure forward secrecy has a cost that most people discover the hard way: when you get a new phone, your old messages cannot come with you, because the keys that opened them are gone by design. Many members want their history.
VOIDEX offers an encrypted history copy that opens with your VOIDEX recovery code, which VOIDEX never holds. For that copy to work, it cannot be forward-secret: the whole point is that a code you keep can open the past on a new device. So anyone who obtained both your encrypted history and your recovery code could read that history.
This is a deliberate trade-off, documented in the public security report, and it is optional. Members who want the strictest posture can switch the history copy off, and then live messages keep their full forward secrecy with no copy behind them. Guidance on protecting the code is in own your keys.
What this means for you
You will never see a ratchet turn. There is no button for forward secrecy and no setting for post-compromise security. What you get is a quieter kind of assurance: if something goes wrong, the damage is contained in time, and the conversation repairs itself.
Encryption that only protects messages while every key stays perfect is fragile. Encryption that assumes something will eventually leak, and limits what a leak can reveal, is built for the real world.
VOIDEX is invite-only. Request access to start a conversation where every message carries its own key, or read the full design on the VOIDEX security page.
Sources
- Signal: The Double Ratchet Algorithm (specification)
- Signal: The PQXDH Key Agreement Protocol (specification)
- Signal: SPQR, post-quantum ratcheting (October 2025)
- Apple Security Research: iMessage with PQ3 (February 2024)
- NIST FIPS 203: Module-Lattice-Based Key-Encapsulation Mechanism Standard
- RFC 9420: The Messaging Layer Security (MLS) Protocol
Enter VOIDEX
VOIDEX is invite-only and free, with no ads and no trackers. Messages are protected by hybrid post-quantum encryption (X25519 with ML-KEM-768) and checked against a public key transparency log. VOIDEX runs in your browser and as apps for Windows and Mac, with iPhone and Android on the way.
Explore the Voidverse
VOIDEX is one private universe: post-quantum encrypted messaging, an anonymous social layer, short video, collectibles and a private window onto the web.



