RSA Is Simple. Deploying RSA Correctly Almost Never Is.
The capstone to our RSA series. The math checks out. Shipping it as written gets you breached. This is the nineteen-year-old attack that proves it, and what belongs in production instead.
RSA, digital signatures, key generation, and post-quantum cryptography — built from first principles. The series that went viral on HackerNews starts here.
The capstone to our RSA series. The math checks out. Shipping it as written gets you breached. This is the nineteen-year-old attack that proves it, and what belongs in production instead.
On April 24, 2026, Project Eleven awarded 1 BTC to researcher Giancarlo Lelli for breaking a 15-bit elliptic curve key on publicly accessible quantum hardware. Here's what that means, why the trajectory matters more than today's number.
Most JavaScript developers never call an RSA function directly. They verify an RS256 token, and two classic attacks turn that into an authentication bypass — both demonstrated here, both fixed by one line.
Authentication is a cornerstone of contemporary applications. Virtually every app demands user login, identity verification, and secure sessions. Though it's ubiquitous, many developers implement authentication without
Two papers dropped at the end of March. Both said the same thing in different ways: the quantum threat to elliptic curve cryptography is closer than we thought.
I use AI as a tool. I'll say that upfront. Claude helps me write frontends faster. It handles search queries that Google stopped being useful for
A deep-dive into the full cryptographic stack powering every HTTPS connection — RSA-OAEP, AES-GCM, ECDHE key exchange, and a working TLS 1.3 handshake simulation, all built in pure Python from first principles.
RSA-2048 can be broken with fewer than 100,000 qubits. What that means for TLS, certificate infrastructure, and the post-quantum transition already underway.
Encryption transforms readable data into unreadable ciphertext that only someone with the right key can reverse. It's what makes HTTPS, messaging apps, banking, and password storage work. Here's how it actually functions.
Signing is encryption with the keys swapped, and that symmetry is exactly what makes the naive implementation breakable. Here are two forgeries executed against textbook RSA signatures, and what PSS does that hashing alone cannot.
JavaScript cannot do RSA with numbers. Not slowly, not imprecisely — at all. The largest modulus a Number can handle is 26 bits and RSA needs 2048, and the failure is silent. Here's the implementation that works and why.
Cipher.getInstance("AES") compiles, runs, encrypts, decrypts, and hands you the weakest mode in the box. Here is the OpenJDK source that makes that decision, and the line where ECB gets chosen for you.