4 ms·
This part, yikes: > As our encryption is asymmetric, you may be asking how the client decrypts messages send by the server if it only has a public key. To do t
by FujiApple 4y ago
This part, yikes:
> As our encryption is asymmetric, you may be asking how the client decrypts messages send by the server if it only has a public key. To do this the game exploits an interesting quirk of RSA cryptography, its possible to encrypt with the private key and decrypt with the public key. This is exactly what happens when the server sends the client message. For anyone contemplating doing this though, don’t, it’s terrible for a number of reasons. You can read some of these reasons here, written by someone far more knowledgeable about cryptography than myself.
Great effort reverse engineering the protocol and producing an enjoyable write up.
- vlovich123 4y agoThat quote doesn’t seem to appear in the article, or at least not anymore? I was curious to read the reasons. The ones that come to mine are the obvious ones that EC is significantly faster and more secure and that you should only use asymmetric to negotiate a symmetric key exchange (eg ECDH) since symmetric is going to be even faster and suitable for real-time streaming.
- cybrox 4y agoThe quote is from the second article in the series. You can find it here: https://timleonard.uk/2022/06/02/reverse-engineering-dark-souls-3-networking-part-2 https://timleonard.uk/2022/06/02/reverse-engineering-dark-so...
- jakobdabo 4y ago> its possible to encrypt with the private key and decrypt with the public key Isn't it just signing/verifying? I.e. "encryption" with a private key is how RSA is being used to sign, and "decryption" with a public key - used to verify the signature.
- jpnc 4y agoI thought so too. Encrypt the hash with private key -> decrypt with public key and check the hash.
- FujiApple 4y agoThis could well be it, though if the plaintext isn’t sent (unclear from the article if it is, I think not?) then all the client can really do is decrypt with public key and check that the output appears well formed, which may be good enough. It would seem odd, however, that client -> server is encrypted but unsigned whereas server -> client is signed but unencrypted. My guess, for what it’s worth, is that somebody at the company insisted that all comes must be encrypted and so they cobbled this together along with the obfuscation of the public key the author describes.
- sascha_sl 4y agoConsidering it is the basis for the entirety of RSA PKI / RSA signatures, I wouldn't call being able to decrypt with the public key a quirk.
- deleted 4y ago[deleted]