4 ms·
I’m really curious about this as others have said similar things. What else is missing?
by laluser 5y ago
I’m really curious about this as others have said similar things. What else is missing?
- DarkmSparks 5y agoThats a secret. Pretty sure the point is you should only use NSA approved implementations.
- criticaltinker 5y agoThings like constant-time arithmetic are essential for safe and correct cryptography [1]. Treatments like the OP are accessible and can be helpful for beginners to understand RSA and public key crypto at a high level. However, the tradeoff is that critical details like side-channels are often neglected or not mentioned at all. [1] https://eprint.iacr.org/2021/1121.pdf https://eprint.iacr.org/2021/1121.pdf
- DarkmSparks 5y agothe article links to side channel attacks and making it constant time. so hardly a valid accusation that it missed them.
- lazide 5y agoFor one, it is critical that you don’t use the same key for signing as you do for encryption. Also, it is critical you use padding techniques that don’t allow chosen plaintext or similar. Ideally, you also don’t ever encrypt the actual data itself directly with RSA, as 1) it’s slow, and 2) stock RSA is deterministic (same key, same input, same output) and if you encrypt a lot of data that way you’ll end up leaking significant details that make it easier to guess the key or fake future correspondence. OAEP helps immensely here, but what is even better is using RSA + OAEP to exchange a disposable one time use symmetric key of decent strength (Say AES 256 bit) which the content is then encrypted in (say using CTR or GCM mode), which doesn’t have any of these problems.
- dataflow 5y agoTo give one potential example: it appears that some primes are likely to be less secure than other primes. I don't really have much background info on this to provide here, so you'll want to Google around, but I'll leave a couple of links to more reading. (There are probably better links I'm not aware of.) I just know enough to know that it's a bad idea to implement asymmetric cryptography without fully understanding the number theory behind it. [1] https://mathoverflow.net/q/283767 https://mathoverflow.net/q/283767 [2] https://crypto.stackexchange.com/a/47733 https://crypto.stackexchange.com/a/47733
- olliej 5y agoThe article mentions timing, though it’s important to realize that RSA is resistant to constant time - you can mitigate this with some random work making use of ‘X mod N’ is the same as ‘AXA^-1 mod N’ You also can’t use the same key for signing and encryption. You have to be sure your primes are actually prime (there have been bugs where ‘primes’ turned out to be composite) Even if they are prime, some classes of prime are weaker for some reason involving maths I never understood. I know there are more but my TLS days are mercifully far behind me :)