3 ms·
This could well be it, though if the plaintext isn’t sent (unclear from the article if it is, I think not?) then all the client can really do is decrypt with pu
by FujiApple 4y ago
This could well be it, though if the plaintext isn’t sent (unclear from the article if it is, I think not?) then all the client can really do is decrypt with public key and check that the output appears well formed, which may be good enough.
It would seem odd, however, that client -> server is encrypted but unsigned whereas server -> client is signed but unencrypted. My guess, for what it’s worth, is that somebody at the company insisted that all comes must be encrypted and so they cobbled this together along with the obfuscation of the public key the author describes.