140,841 followers
@ChrisPeikert The reduction for e=65537 is not good but I don’t remember whether it’s just loose or the runtime is unusually high. Ditto the reduction for TLS’s PKCS#1v1.5. And there are RSA-based generators that also have these problems. https://t.co/Hpe9