Move Fast
A service encrypts short messages with RSA, e=3, and never bothers with padding. What could go wrong?
A startup's internal tool RSA-encrypts short flags for "security", using e = 3 because it's fast, and skips padding because "it's just internal, who cares."
The modulus is large — far larger than the cube of the message. That detail matters more than they think.
33991036134426362306408271035380682121493070580665211788675360579490223508942835693335262741942843824374460748713009817248036667015315563859193016467479147541162698649036046326117551294737558849538859995285343129835402448927933152386159000451741900313303405330425041536491103934821
Hints
Checked entirely in your browser — nothing you submit here leaves your device.
Background on this technique
Up next
The Fastest Cipher →An engineer wanted RSA encryption without the performance cost. They found a way.