[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: RSA Signature Padding



The way I read this is that 1.5 is handcrafted to mitigate known attacks
while PSS use a more generic and provable secure approach. But neither of
them are broken.

Would that be a correct assessment?

/Stefan


On 09-06-13 2:10 PM, "Peter Gutmann" <pgut001@xxxxxxxxxxxxxxxxx> wrote:

> 
> "Santosh Chokhani" <SChokhani@xxxxxxxxxxxx> writes:
> 
>> There is benefit to PSS over 1.5.  The paper points that out.
> 
> There is a purely theoretical benefit, but weighed against the *massive*
> practical downside of going to PSS I doubt it'll carry much weight...
> 
> Peter.
>