3 ms·
> Although accessed, all passwords, social security numbers and tax form information remain safely encrypted with a 2048-bit RSA key. > ... > We protect our u
by 21echoes 11y ago
> Although accessed, all passwords, social security numbers and tax form information remain safely encrypted with a 2048-bit RSA key.
> ...
> We protect our users’ passwords with a hashing scheme called ‘bcrypt’ and randomly salt each individual password. Bcrypt is non-reversible, so passwords cannot be “decrypted.” We do not store plaintext passwords anywhere.
Updated post now says the above.
- Buge 11y agoGenerally you don't encrypt actual data with rsa, you encrypt a symmetric key with rsa, then encrypt the actual data with the symmetric key with symmetric encryption. An obvious question is what granularity is the symmetric key for their data. A different one for each piece of data? Usually rsa is used when the source of the data never needs to read the data again. Usually for example like sending an email. The sender encrypts it and sends it, but the sender cannot decrypt it. Why were they using rsa for the tax information? Were there multiple servers and the server that creates the information is not trusted with being able to ever read the information later?
- Slartie 11y agoAFAIK there is nothing stopping you from encrypting arbitrary amounts of data directly using asymmetric algorithms like RSA. The scheme you describe is implemented because asymmetric crypto is dead-slow compared to symmetric crypto, so the amount of data to be encrypted using an asymmetric algorithm is kept to a minimum by just encrypting a random symmetric key, which is then used to encrypt large amounts of data with a fast symmetric algorithm. Since the data that was encrypted in this case is inherently tiny (social security numbers etc.), I'd think it would be a good idea to directly encrypt this with an asymmetric algorithm, thereby reducing the complexity of the entire mechanism, which is generally beneficial for security as well as maintainability. But I'm wondering as well about the reasons for choosing an asymmetric algorithm in the first place. Typically, symmetric algorithms are used for such cases in which the entity that encrypts something is the same entity that needs to be able to decrypt it later. It's not that this could not be implemented as well using asymmetric crypto, but it somehow defies the whole point of the asymmetry.
- kwe 11y agoMaybe what they meant is that they hash using bcrypt and then encrypt the hashes?