Is this trying to show that Duck Duck Go just enabled PFS (perfect forward secrecy)?
Chrome says, for the blog mentioned in your profile:
"The connection is encrypted using AES_256_CBC, with SHA1 for message authentication and ECDHE_RSA as the key exchange mechanism."
"ECDHE" means elliptic curve Diffie-Hellman exchange. This means your server, whatever it is, is configured to support perfect forward secrecy. If you're running your own server, you're probably using some recent distribution or Apache release that defaults to enabling ECDHE. Otherwise, your host may have done such configuration themselves.