3 ms·
Why don't you use the standard openssl RSA encryption function to encrypt the entire file, rather then encrypt a plaintext passphrase? I don't know of an imple
by asharp 16y ago
Why don't you use the standard openssl RSA encryption function to encrypt the entire file, rather then encrypt a plaintext passphrase?
I don't know of an implementation that uses RSA encryption that doesn't use RSA to encrypt a (heavily padded, very random) key which they then use to encrypt the final payload using say AES or IDEA (in the original PGP).
- asymptotic 16y agoSpeed, because cryptanalysis via cipher-text only attacks becomes easier as you get more and more ciphertext associated with a given key, and because if someone attempts to analyse a memory core dump or the memory space of your computer hopefully the only data available is the session key, rather than the full decrypted RSA private key. See: https://secure.wikimedia.org/wikipedia/en/wiki/Session_key https://secure.wikimedia.org/wikipedia/en/wiki/Session_key https://secure.wikimedia.org/wikipedia/en/wiki/Ciphertext-only_attack https://secure.wikimedia.org/wikipedia/en/wiki/Ciphertext-on... http://academic.csuohio.edu/zhao_w/teaching/Old/EEC693-S07/lecture6.ppt http://academic.csuohio.edu/zhao_w/teaching/Old/EEC693-S07/l...
- asharp 16y agoThat makes no sense. You create some random key K. You encrypt k using the public key of the recipient, ie. e(k). You encrypt the message using K. You send both of those to the recipient. A cyphertext only attack can recover K from your message M. It is not then possible to recover a private key from K. In neither case do you ever have the private key, as such it cannot ever be recovered from a core dump. In this script it seems like they are simply doing this twice, for some unknown reason.
- asymptotic 16y agoSorry, there seems to have been a misunderstanding; I completely agree with you. I thought you were asking "Why bother using sessions keys, rather than encrypt the whole message using RSA?". My bad.
- tptacek 16y agoYou got downvoted, and maybe I've misinterpreted the thread, but my perception was: * Parent commenter thinks messages should just use RSA, and not RSA+AES. * You try to explain why he should use RSA+AES instead of RSA. * He tries to post an analysis of why to use RSA-only. Can I just step in to say: (a) using RSA only is way slower, like you said, and (b) it is significantly harder to make bulk RSA encryption secure than it is to make bulk AES encryption secure, just like you said?