I thought FS only protected other sessions from leak of your current session key. How does it protect against passive recording of the session and later attacking of the recorded session in the future?
If on the other hand you use a FS key exchange (like ECDHE), and the session is recorded, and the server's private key is obtained, the session key cannot be recovered (that's a property of ECDHE or any forward-secure key exchange), and none of the traffic is decryptable.
Of course it can, but only for that specific session.
You would need to compromise the _ephemeral session key_ which is difficult because it is discarded by both parties when the session is closed.
Compromising the RSA key backing the certificate allows _future_ impersonations of the server, which is a different attack altogether.