etalas

etalas at

Well, if they had backdoors in those they wouldn't need to ask the companies for the keys to decrypt all the encrypted communications they archived (they can get the session key used for a SSL-connection with the server's SSL-key and the archived traffic of key negotiation phase).
If everyone would implement ephemeral session keys / perfect forward secrecy they would try to a) get a way to get the cleartext from the company (or push for means to collect it inside the company) and b) probably also try harder to get backdoors in the software on both ends.