3 ms·
Also, this limitation is easily worked around. 1. Use a digital signature. 2. Encrypt your signed message using Hybrid Encryption. After your recipient decry
by CiPHPerCoder 8y ago
Also, this limitation is easily worked around.
1. Use a digital signature.
2. Encrypt your signed message using Hybrid Encryption.
After your recipient decrypts your message (which, as Thomas notes, has AEAD), they can then verify your signature.
- zokier 8y agoI would think you'd generally want to do it the other way around and sign the ciphertext instead.
- CiPHPerCoder 8y ago"Just sign this opaque blob"? Digital signatures aren't in the scope of the cryptographic doom principle. Generally, if you're signing a document, you want it to be really clear that you signed what it says.
- zokier 8y agoCrypto is confusing.
- CiPHPerCoder 8y agoIt is, indeed.