> Yes. Exactly. Only the transport part is protected.
Well, isn't that valuable?
> With messaging, saving old messages is more or less the default. When that happens the value of forward secrecy is negated.
It's not negated because a passive attacker that records communications and then, in the (potentially far) future, somehow can obtain the key (say, by exploiting some weakness and/or brute-forcing), still cannot decrypt your past communications, regardless of whether everybody saves old messages or not.
By passive attacker, I mean someone like the NSA, your ISP, your messaging provider, the server/P2P host that relays your messages, etc.
> If you want your old messages to be gone, you (and your correspondent) actually have to get rid of them.
But that's not what forward secrecy is designed to do, is it? It's designed to prevent third parties who can record the encrypted end-to-end communication from decrypting past messages when/if they can obtain your key.
It's not designed for making old messages be gone.
> Terminology quibble. I think this would be normally described as recording the encrypted messages off the wire. MITM implies than an attacker is impersonating one or more correspondents.
Yes, sorry, I meant a "passive man-in-the-middle attacker".