RSA Is Simple. Deploying RSA Correctly Almost Never Is.
The capstone to our RSA series. The math checks out. Shipping it as written gets you breached. This is the nineteen-year-old attack that proves it, and what belongs in production instead.
The capstone to our RSA series. The math checks out. Shipping it as written gets you breached. This is the nineteen-year-old attack that proves it, and what belongs in production instead.
Most JavaScript developers never call an RSA function directly. They verify an RS256 token, and two classic attacks turn that into an authentication bypass — both demonstrated here, both fixed by one line.
Encryption transforms readable data into unreadable ciphertext that only someone with the right key can reverse. It's what makes HTTPS, messaging apps, banking, and password storage work. Here's how it actually functions.
Signing is encryption with the keys swapped, and that symmetry is exactly what makes the naive implementation breakable. Here are two forgeries executed against textbook RSA signatures, and what PSS does that hashing alone cannot.
JavaScript cannot do RSA with numbers. Not slowly, not imprecisely — at all. The largest modulus a Number can handle is 26 bits and RSA needs 2048, and the failure is silent. Here's the implementation that works and why.
Key generation works, encryption round-trips, the math is provably right — and an attacker can still recover the private key by timing your decryptions. Here are both defenses, measured, with what they actually cost.
Part 1 used 15-bit primes and only encrypted integers. Making it usable means generating 1024-bit primes and chunking bytes — and the standard way to do the second one silently destroys data on inputs the tests never cover.
Every HTTPS connection you have ever made runs on a 1978 paper. You can build the core of it in about fifty lines of Python — and then see exactly why those fifty lines would get you destroyed in production.