|
|
|
|
|
by obrhubr
709 days ago
|
|
Thanks for the feedback, appreciate it. I wanted this to more entertaining than informative, but I understand why this might mislead. - I agree that the section on pkcs#1 is at this point irrelevant, I left it in just to mention that fact. But I will probably take it out now :) - Concerning the part of misusing RSA: My understanding is that you usually append the signature at the end, after a copy of the data which is not done here. I believe they are misusing it here because no library for RSA supports this use case, to decrypt using a public key you always have to provide the message and signature. This isn't possible here because the message is encrypted.
So I think they are misusing RSA. |
|
Nonetheless, please keep writing! It was an entertaining read for me.
Salutations du Luxembourg :-)