4 ms·
You're right and I'm wrong. Mea culpa. I dashed these off quickly. Unfortunately I can't edit anymore, so the erroneous #5 will have to stay there. The main b
by sdevlin 13y ago
You're right and I'm wrong. Mea culpa. I dashed these off quickly.
Unfortunately I can't edit anymore, so the erroneous #5 will have to stay there.
The main bad thing here is the null padding (covered in #4). This gives the attacker a lot of knowledge of the plaintext (the most significant bytes are all null), which can be used to decrypt if this format is validated on the other end. Bleichenbacher's attack only requires knowledge of one plaintext byte (the leading 02h), and we have many.