4 ms·
Thanks! This is an excellent list of potential issues. "What are you going to use to actually encrypt messages? You don't want to directly use the public key
by ricksharp 9y ago
Thanks!
This is an excellent list of potential issues.
"What are you going to use to actually encrypt messages? You don't want to directly use the public key primitives to do this."
I'm not sure what you mean by this.
Could you explain why there is a need for another encryption protocol beyond a public/private key encryption?
If the protocol is secure against brute force attack, both the public key and the encrypted messages could be open and would not create a vulnerability to the private key.
What am I missing?
- tptacek 9y ago* Assymetric transforms are much, much slower than the AES transform or any other block or stream cipher. * In most cases, an asymmetric transform gives you a deceptively small amount of headroom within which to fit your data before losing security. * asymmetric transforms are less safe to implement than simple authenticated symmetric ciphers. * for that matter, cost-effectively authenticating messages will require "symmetric" primitives anyways. * modern asymmetric algorithms (like Curve25519) don't "directly" support encryption. That's just off the top of my head. It is hard to think of a single competent public key cryptosystem that encrypts directly with the asym transform.