3 ms·
I thought so too. Encrypt the hash with private key -> decrypt with public key and check the hash.
by jpnc 4y ago
I thought so too. Encrypt the hash with private key -> decrypt with public key and check the hash.
- FujiApple 4y agoThis could well be it, though if the plaintext isn’t sent (unclear from the article if it is, I think not?) then all the client can really do is decrypt with public key and check that the output appears well formed, which may be good enough. It would seem odd, however, that client -> server is encrypted but unsigned whereas server -> client is signed but unencrypted. My guess, for what it’s worth, is that somebody at the company insisted that all comes must be encrypted and so they cobbled this together along with the obfuscation of the public key the author describes.