- 94comments
- 106comments
- 82comments
- 62comments
- 433comments
- 72comments
- 17comments
- 49comments
- 285comments
- 18comments
- 337comments
- 39comments
- 81comments
- 15comments
- 32comments
- 92comments
- 6comments
- 2comments
- 106comments
- 267comments
- 1comments
- 4comments
- 89comments
- 72comments
- 54comments
- 1comments
- 13comments
- 71comments
- 100comments
- 24comments
Wouldn't it be better to feed the RSA public key into an existing message encryption system like gpg? There are a few things you could improve that way:
* No message integrity - it would be good to be able to sign and encrypt.
* Encrypting the same plaintext twice gives the same ciphertext (there is no randomness). This means that an attacker can confirm if a given ciphertext corresponds to a suspected plaintext.
* RSA is comparatively slow; it is usually better to encrypt a symmetric key with RSA and then encrypt the message with the symmetric key.
Sure. This is intended as a quick way to send small bits of sensitive information over email, chat, etc.