
Marty
The lecture explains correctly that you need ECDHE for PFS (actually, DHE also works and dóes exist for other predefined policies), but then goes on to repeat that because of that you always need to choose the 2016 policy ‘because it supports almost everything’. That’s really the wrong conclusion: other policies are equally supportive of PFS.
And choosing a policy because it supports everything in a security lecture is also doubtful advice: there’s a reason why the newer policies dropped support for certain ciphers and that’s because they’re considered weak and outdated.