← All challenges
RSA·medium·25 pts

Move Fast

A service encrypts short messages with RSA, e=3, and never bothers with padding. What could go wrong?

A startup's internal tool RSA-encrypts short flags for "security", using e = 3 because it's fast, and skips padding because "it's just internal, who cares."

The modulus is large — far larger than the cube of the message. That detail matters more than they think.

Ciphertext (M³, as a decimal integer)

33991036134426362306408271035380682121493070580665211788675360579490223508942835693335262741942843824374460748713009817248036667015315563859193016467479147541162698649036046326117551294737558849538859995285343129835402448927933152386159000451741900313303405330425041536491103934821

Hints

Checked entirely in your browser — nothing you submit here leaves your device.

Background on this technique

Up next

The Fastest Cipher →

An engineer wanted RSA encryption without the performance cost. They found a way.