• PierceTheBubble@lemmy.ml
    link
    fedilink
    English
    arrow-up
    8
    ·
    20 hours ago

    So for RSA without padding, a threat actor could request lots of tokens (without getting rate-limited?), and use that as information to more precisely focus efforts to brute-force the key, and thereby reducing the number of operations required to do so? Or am I misunderstanding it?