4 ms·
Just to clarify, encryption happens with the public key and decryption with the private.
by genry 7y ago
Just to clarify, encryption happens with the public key and decryption with the private.
- animeshg 7y agoThanks
- tialaramex 7y agoThis probably doesn't help because in practice that's not how it's done at all. For a modern HTTPS connection what happens is that two participants use a Key Agreement process which results in them both knowing a random secret that nobody else knows. This secret is ephemeral which means once the connection closes they'll both forget what it was. They both use this shared secret to choose the same several symmetric keys and use those keys to encrypt (and decrypt) the actual HTTP traffic. For HTTPS in particular the main asymmetric cryptography is used for signatures, proof that this is really news.ycombinator.com for example. Your web browser doesn't encrypt messages to news.ycombinator.com but after Key Agreement happens the server will send a message proving it participated in this agreement you've just done, signed using its private key, and your browser uses the public key to check that this is a genuine signature.
- newscracker 7y agoNo, it doesn’t work that way for HTTPS. Public Key Cryptography is a relatively expensive operation. So the public/private keys are used to create and exchange a temporary symmetric encryption key. That symmetric encryption key is used to encrypt and decrypt the HTTPS requests and responses later by the client and the server. What you describe is used that way when you want to send, say encrypted emails to someone else when you have their public key.