11 ms·
How RSA Works: TLS Foundations
- kss238 9y agoCan someone explain this section some more >Considering that we need a distinct key for each individual, that exchanging keys with each person would be a significant computational burden, and that there are more cryptographic functions needed than simply exchanging keys, new methods arose. Isn't this exactly what RSA does, exchanging a private symmetric key with asymmetric crypto? The next paragraph makes it seem like RSA does something different.
- goodroot 9y agoMost excellent question, kss238. The next part in the series, which breaks apart the different parts of a TLS ciphersuite, was just published: http://fly.io/articles/how-ciphersuites-work/ http://fly.io/articles/how-ciphersuites-work/ It should answer your question, in similar spirits to that of this article. Thank you for reading and I wish you well.
- bogomipz 9y agoWhat is the rest of the context of the Golang code snippet in that that link?
- matahwoosh 9y agoIt's most likely to be Fly-specific, but you could replicate this behavior with passing appropriate to tls.Config#GetCertificate (https://golang.org/pkg/crypto/tls/#Config https://golang.org/pkg/crypto/tls/#Config). You could then have something like that : GetCertificate: func(helloInfo *tls.ClientHelloInfo) (*tls.Certificate, error) { return myGetCertificateImplementation(checkClientSupportForECDSA(helloInfo)) } You would see what curves/ciphersuites are supported by the client and check that against what you'd be supporting (if you use LE than that's more than likely going to be ECDSA with P-256). You would then return ECDSA cert (if one exist) for supporting clients and fallback to RSA certs. :boom: :D
- bogomipz 9y agoThanks, cheers.
- matahwoosh 9y agoyou can also use RSA for actual encryption (like PGP) or for signing/verifying. ECDHE is better for key exchange, and ECDSA is better for signing/verifying. Check out goodroot's link!
- blattimwind 9y agoRSA encryption has been shown time and time again to be a really bad idea, to the point that it was removed from TLS 1.3 early on.
- matahwoosh 9y agowhat encryption are you talking about? IIRC, RSA has only been used for key exchange or authentication (sign/verify) in SSL/TLS. Even in the old days up to SSL 3.0, RC4 or (3)DES was used for actual (symmetrical) encryption.
- tptacek 9y agoRSA is a bad idea in key exchanges as well.
- matahwoosh 9y agotptacek: I think this sub-thread has been mainly to explain what RSA could be used for, not that it would be a good idea. On the side note, I have been positively surprised to see how many devices support ECDHE key exchange. Also, do you have a good resource that explains the drawbacks of RSA key exchange in more details?
- wolf550e 9y agohttps://en.wikipedia.org/wiki/Forward_secrecy https://en.wikipedia.org/wiki/Forward_secrecy
- matahwoosh 9y ago
- AngeloAnolin 9y agoNoticed that this page worked on Chrome, but not on FF. On FF (57.0.2) Windows 7, the message is as below: Error 1010 Ray ID: 3cc3b2b85d0b9300 • 2017-12-12 21:15:17 UTC Access denied What happened? The owner of this website (fly-io.ghost.io) has banned your access based on your browser's signature (3cc3b2b85d0b9300-ua48). Not sure if the author or website owner had a beef with FF.
- dguaraglia 9y agoSame here. EDIT: never mind, now it's giving the same error on Firefox too, only Safari works. Go figure.
- mrkurt 9y agoThis is CloudFlare helpfully preventing you from DDOSing Ghost. We're working on bypassing CF for our ghost stuff, sorry about that.
- judge2020 9y agoIf you have extra page rules, the "disable security" tick on `https://fly.io/articles/*` https://fly.io/articles/*` may stop this kind of protection.
- mrkurt 9y agoIt's not actually our CloudFlare site, unfortunately, we're proxying Ghost Pro through our service (so we can serve `/articles/` on the same hostname).
- deleted 9y ago[deleted]
- deleted 9y ago[deleted]
- manigandham 9y agoTry it without the "?twitter" querystring which looks to be cached: https://fly.io/articles/how-rsa-works-tls-foundations/ https://fly.io/articles/how-rsa-works-tls-foundations/
- mabbo 9y agoI find the description of the RSA math pretty confusing. And I'm saying that with a minor in math and a CS degree specializing in security; I've don't this before, just not in a while. For example: >In order to generate e, we'll need to find a random prime number that has a greatest common divisor (GCD) of 1 in relation to ϕ(n). How can a prime number have any divisor that isn't 1, let alone a gcd? Either that's mistaken, or it's unnecessary to state. There's also no explanation of what purpose the totient value is. The author simply states it's needed, but not what value it provides. In short, it feels like it's written for people who already know the answers, not for people trying to learn.
- baby 9y ago> How can a prime number have any divisor that isn't 1 What they mean by "gcd of 1 in relation to" is what we call "coprime". 5 and 3 are coprime because nothing but 1 divides both at the same time. > what purpose the totient value is it allows you to compute the private key out of the public key (only possible if the totient is coprime with the public key)
- mabbo 9y agoYes, but why? Just saying "here's the algorithm" doesn't really explain why it works.
- matahwoosh 9y agoFair point! I think that quote should read "a random coprime to [...] to ϕ(n)". Then it makes sense. There's a lot of math behind RSA computation and we were trying to distill as much as we could, but it's not perfect. We have added a simple example to tie everything together, but it just means that you might have to plow thru the heavy bits first. Now, the totient it needed to compute your encryption and decryption values. You start with getting 2 primes: n = p * q then you compute the totient: ϕ(n) = (p-1)(q-1) then you compute your encryption and decryption values: e x d = 1 mod ϕ(n) Then your private key will be be a pair (d, n) and public key will be (e, n). Then, given that m is message and c is cipher: Encryption F(m,e) = m^e mod n = c Decryption F(c,d) = c^d mod n = m
- 9y ago
- orliesaurus 9y agointeresting, these folks at fly.io sure put out a lot of content!
- hannob 9y agoA better title would be "How RSA does not work". I'm a bit annoyed by many of these crypto introductions that explain textbook RSA, which is not something anyone uses in a real world application. It is crucial for RSA to use a padding mode and that's where all the fun comes in and what decides about how secure the thing you're building is.
- sethgecko 9y agoI just made a quick Python implementation (3.6+ only as it uses the secrets module) https://github.com/mcdallas/rsa https://github.com/mcdallas/rsa
- lou1306 9y agoNice! I also did something similar during my basic crypto course. I'll just show my implementation of Wiener's attack, which shows that RSA can be super weak if you don't choose your private key with a grain of salt. https://gist.github.com/lou1306/df1bfa60e247b4084149139a97dab761 https://gist.github.com/lou1306/df1bfa60e247b4084149139a97da...