5 ms·
RSA is just notoriously difficult to implement correctly, unless you're some kind of crypto expert. https://www.youtube.com/watch?v=lElHzac8DDI https://www.yout
by michielderhaeg 7y ago
RSA is just notoriously difficult to implement correctly, unless you're some kind of crypto expert.
https://www.youtube.com/watch?v=lElHzac8DDI https://www.youtube.com/watch?v=lElHzac8DDI
- tptacek 7y agoCryptographers who are much smarter than me disagree with me when I say this but I think there's some truth to this; RSA has, by design, more footguns than the comparable systems you'd create with a modern curve design, starting with the fact that the "directly encrypt with the RSA block transform" primitive is a misfeature.
- Ar-Curunir 7y agoTbh RSA should be deprecated; there's really almost no user for it in standard crypto IMO
- jcims 7y agohttps://blog.trailofbits.com/2019/07/08/fuck-rsa/ https://blog.trailofbits.com/2019/07/08/fuck-rsa/
- commandlinefan 7y agoIt's been all but deprecated in TLS 1.3... however, it's been replaced with ECDH/ECDSA - which the NSA is now recommending against: https://threatpost.com/nsas-divorce-from-ecc-causing-crypto-hand-wringing/115150/ https://threatpost.com/nsas-divorce-from-ecc-causing-crypto-...
- wolf550e 7y agoThat's mostly bullshit. NSA is just saying "don't start a multi-year project to upgrade from RSA to NIST P-256 because you will not be finished with that upgrade before we'll ask you to upgrade to a recommended PQ crypto scheme". There is nothing wrong with X25519 and Ed25519, except that they are vulnerable to quantum computers (like anything else currently in use).
- debatem1 7y agoAll crypto is difficult to get right unless you're a crypto expert. RSA is not unusual in this regard. The thing that is unusual about RSA is how many people /kind of/ understand it. Crypto people who dislike RSA say that this leads to a proliferation of terrible RSA implementations, and that it is therefore more dangerous to use than eg ECC. Crypto people who like RSA say that its relative accessibility makes it a more popular target, and that in the absence of a catastrophic break the more-studied cryptosystem should be assumed to be more secure. Personally I've spent some time recently with badly implemented ECC, and I don't think the mistakes being made there are fundamentally different from or rarer than the mistakes you see in poorly implemented RSA.
- nullc 7y ago> The thing that is unusual about RSA is how many people /kind of/ understand it. I wouldn't say this is that unusual about RSA but your point is otherwise good. There are a lot of mechanistic "this is how you do ECC" writeups resulting in a lot of people who think they understand it while having no real intuition for it (and particular for the security considerations). Over and over-again in cryptography the biggest danger is overconfidence. If you aren't scared of vulnerabilities hiding behind every seemingly minor decision, then you're in trouble. Probably the worst "kind of understand it" I've seen in cryptography is shamir secret sharing, RSA comes right behind that. The big difference between RSA and ECC is that for a long time people were mystified by the group operations while they felt they understood modular multiplication, but the rise in mechanical group law tutorials has leveled the playing field a lot there.
- debatem1 7y agoInteresting, do you mind if I ask what kind of environment you work in? Most of the non-crypto people I know will mumble about primes and factors when asked how public key crypto works, but maybe I'm just wildly out of date.
- mehrdadn 7y ago> All crypto is difficult to get right unless you're a crypto expert. RSA is not unusual in this regard. Maybe all asymmetric crypto. Symmetric can be a lot easier.