3 ms·
Yeah, the implementation here obviously has problems, but as a learning exercise, I do still think it's worth implementing RSA (or anything else complex) in wha
by thraxil 3y ago
Yeah, the implementation here obviously has problems, but as a learning exercise, I do still think it's worth implementing RSA (or anything else complex) in whatever language you're comfortable with. Personally, I implemented RSA in JavaScript back in 1998 as an exercise. I had to roll my own basic BigNum implementation and it didn't perform well enough to handle non-trivial key or message sizes, but I still think it was valuable for my education (and fun).
- tialaramex 3y agoIf it was "valuable for my education" what did you learn? Your take away seems to have been that your toy RSA implementation "didn't perform well enough" which isn't a lesson.
- thraxil 3y agoI learned... how RSA works... better than I would have just from reading about the algorithm in a book or from a lecture? Why is it a strange concept that one could learn something by doing rather than just reading/listening? The RSA algorithm isn't inherently about bit-twiddling, but to implement it efficiently for real-world use, you have to get into a lot of those weeds that distract you from the core ideas.
- tialaramex 3y agoI'm not at all convinced that "I made this thing which didn't actually work" constitutes learning more than say the colour-mixing video from "Art of the Problem". In both cases you're only learning the concept, and if you actually do this it won't actually work†. So, why do it rather than just reading about it? Usually our argument for learning by doing is that you're gaining valuable experience of it actually working - but textbook RSA doesn't work, it doesn't deliver security. So the best case is the same as just reading about it or watching a video, except it took much longer. The worst case is that you believe what you're doing (a toy which can't work) is how it actually works (which it isn't) and then you try to apply this incorrect lesson. † Specifically, textbook RSA doesn't achieve security, you're missing a crucial component of a working system which wasn't important to the explanation but is crucial to a working system.
- thraxil 3y agoShould students ever write code then? Most of it's not going to be production quality, so it seems like you think that would be a waste of their time. My experience over and over in life is that I read about something complex, think I understand it, go try to do it, eg, writing a proof or code or teaching it to someone else, and discover that there were some aspects of the thing that I didn't fully understand or had a misconception about. That observation that even very smart people are good at convincing themselves they understand something better than they actually do is basically why the Feynman Technique works so well. I tend to just like to write toy programs and simulations to check my understanding. The resulting prose or program isn't the point, it's all the points you hit in the process where you realize you're missing something. I write small prototypes pretty much every day, learn from them, throw them away, then apply what I learned on the real problem I'm working on. I find that to be an incredibly fruitful approach. I coded up a toy RSA implementation after we had a lecture about RSA in my Number Theory class. And I didn't say that it didn't work; it just obviously didn't perform very well because that wasn't the point (I was very new to programming and working in JS as that was the only environment available to me). I'm sorry I can't pinpoint the exact details of what I learned about RSA a quarter century ago. When I took a Cryptography class a couple years later taught by Michael Rabin, I did very well and felt like I had a better grasp of some of the basic ideas than I would've if I hadn't spent some time working through some basic implementations.