4 ms·
That makes no sense. You create some random key K. You encrypt k using the public key of the recipient, ie. e(k). You encrypt the message using K. You send
by asharp 16y ago
That makes no sense.
You create some random key K.
You encrypt k using the public key of the recipient, ie. e(k).
You encrypt the message using K.
You send both of those to the recipient. A cyphertext only attack can recover K from your message M. It is not then possible to recover a private key from K.
In neither case do you ever have the private key, as such it cannot ever be recovered from a core dump. In this script it seems like they are simply doing this twice, for some unknown reason.
- asymptotic 16y agoSorry, there seems to have been a misunderstanding; I completely agree with you. I thought you were asking "Why bother using sessions keys, rather than encrypt the whole message using RSA?". My bad.
- tptacek 16y agoYou got downvoted, and maybe I've misinterpreted the thread, but my perception was: * Parent commenter thinks messages should just use RSA, and not RSA+AES. * You try to explain why he should use RSA+AES instead of RSA. * He tries to post an analysis of why to use RSA-only. Can I just step in to say: (a) using RSA only is way slower, like you said, and (b) it is significantly harder to make bulk RSA encryption secure than it is to make bulk AES encryption secure, just like you said?