Sign Up

Sign Up to our social questions and Answers Engine to ask questions, answer people’s questions, and connect with other people.

Have an account? Sign In

Have an account? Sign In Now

Sign In

Login to our social questions & Answers Engine to ask questions answer people’s questions & connect with other people.

Sign Up Here

Forgot Password?

Don't have account, Sign Up Here

Forgot Password

Lost your password? Please enter your email address. You will receive a link and will create a new password via email.

Have an account? Sign In Now

You must login to ask a question.

Forgot Password?

Need An Account, Sign Up Here

Please briefly explain why you feel this question should be reported.

Please briefly explain why you feel this answer should be reported.

Please briefly explain why you feel this user should be reported.

Sign InSign Up

The Archive Base

The Archive Base Logo The Archive Base Logo

The Archive Base Navigation

  • SEARCH
  • Home
  • About Us
  • Blog
  • Contact Us
Search
Ask A Question

Mobile menu

Close
Ask a Question
  • Home
  • Add group
  • Groups page
  • Feed
  • User Profile
  • Communities
  • Questions
    • New Questions
    • Trending Questions
    • Must read Questions
    • Hot Questions
  • Polls
  • Tags
  • Badges
  • Buy Points
  • Users
  • Help
  • Buy Theme
  • SEARCH
Home/ Questions/Q 555699
In Process

The Archive Base Latest Questions

Editorial Team
  • 0
Editorial Team
Asked: May 13, 20262026-05-13T11:50:31+00:00 2026-05-13T11:50:31+00:00

I was given advice that I am suspicious about so I’m looking for support

  • 0

I was given advice that I am suspicious about so I’m looking for support here to go back and challenge the advice.

I was advised to use Diffie-Hellman to get both sides to agree on a secret key, use the secret key to generate an AES key, and then use AES to encrypt/decrypt passwords that are being transmitted. Pretty much like the sample code here

When using this scheme, the length of the encrypted password is the same as the length of the unencrypted password. Should I be worried about this?

Before, I was using RSA, encrypting the passwords with the receiver’s public key. This was resulting in an encrypted length of 256 no matter what the password length. Isn’t that better?

  • 1 1 Answer
  • 0 Views
  • 0 Followers
  • 0
Share
  • Facebook
  • Report

Leave an answer
Cancel reply

You must login to add an answer.

Forgot Password?

Need An Account, Sign Up Here

1 Answer

  • Voted
  • Oldest
  • Recent
  • Random
  1. Editorial Team
    Editorial Team
    2026-05-13T11:50:31+00:00Added an answer on May 13, 2026 at 11:50 am

    You can just pad to whatever length with any data. It doesn’t have to be random. As long as it’s all encrypted. I think though that is the least of your worries.

    Note if you use Diffie-Hellman you still need to authenticate the parameters sent, which you probably need to do with RSA.

    The alternatives are:

    1. Use RSA to exchange an encrypted secret key that you then use to encrypt your data.
    2. Use Diffie-Hellman to exchange a secret key and then use RSA to sign values sent to authenticate the transaction.

    If you do all this, then you have to also worry about whether exchanges have been replayed to make you reuse keys etc.

    To be honest if you need to ask this question then you probably are not qualified to write a crypto protocol. They are extremely hard to get right and not for the faint hearted.

    Suggest you use SSL/TLS for your exchange if you need to stream a lot of data. PGP/PKCS#7 if you just need to send a single message.

    • 0
    • Reply
    • Share
      Share
      • Share on Facebook
      • Share on Twitter
      • Share on LinkedIn
      • Share on WhatsApp
      • Report

Sidebar

Related Questions

Could someone prove to me that the advice given here (copied below) regarding removing
A while back I was given the advice to not use the GET approach
After following the great advice given in a thread about service beans I have
One of the advice given by Joshua Bloch is that, class should be designed
I followed the advice given here in several posts on how to declare global
I'm following the advice given here in order to find partial words with elasticsearch:
I've read through the web after being given advice to use the jbjs SDK
I have just merged two repositories following advice given here . Since both repositories
Is the advice given in this oft-cited MSDN article still considered sound for converting
Many thanks for the advice you have given me thus far. Using testbenches is

Explore

  • Home
  • Add group
  • Groups page
  • Communities
  • Questions
    • New Questions
    • Trending Questions
    • Must read Questions
    • Hot Questions
  • Polls
  • Tags
  • Badges
  • Users
  • Help
  • SEARCH

Footer

© 2021 The Archive Base. All Rights Reserved
With Love by The Archive Base

Insert/edit link

Enter the destination URL

Or link to existing content

    No search term specified. Showing recent items. Search or use up and down arrow keys to select an item.