Implementing RSA from Scratch in JavaScript
coderoasis.com
coderoasis.com
The code here doesn't even work, partly because it calls euclideanAlgorithm when the author means extendedEuclidean, but also because Javascript only has 53-bit integers and the modular-multiplication code uses [edit] 60-bit intermediates when N is 30 bits long.
https://developer.mozilla.org/en-US/docs/Web/JavaScript/Refe...
> The operations supported on BigInt values are not constant-time and are thus open to timing attacks. JavaScript BigInts therefore could be dangerous for use in cryptography without mitigating factors.
Without checking the source code to understand their exact implementation, it seems questionable to implement cryptography algorithms for serious use in JavaScript.
> It's better to use Python, which at least has bignums.
I agree with the sibling commenter that this seems to be automatically generated. The disclaimer is weird, you don't just use a random rsa implementation found in a blog post "with careful consideration and expert guidance". The article's structure is weird, it's just a bullet list of steps and then code dump. It gets many details wrong (code won't run, explanation seems to be mixing up euler & carmichael totients, ...). etc.
It is somewhat scary that this got to the front page at all.
Many red flags here:
- Look at the text below the headers "Explaining RSA Cryptography" and "Explaining RSA Cryptography with JavaScript". Both paragraphs start with the exact same text. I believe there are far more chances that this was generated by a machine rather than a human.
- Look at the math! There is a code block where it says "scssCopy" -- the "Copy" is generally garbage from machine generated text+code snippets.
- The code has a missing function, `lcm`. Author has forgotten to include it, which can be a human or machine error.
This kind of episode makes me wonder if I should continue posting, suggest that people filter everything through an LLM, or just resign to the botspamcallypse.
In both cases you're only learning the concept, and if you actually do this it won't actually work†. So, why do it rather than just reading about it? Usually our argument for learning by doing is that you're gaining valuable experience of it actually working - but textbook RSA doesn't work, it doesn't deliver security.
So the best case is the same as just reading about it or watching a video, except it took much longer. The worst case is that you believe what you're doing (a toy which can't work) is how it actually works (which it isn't) and then you try to apply this incorrect lesson.
† Specifically, textbook RSA doesn't achieve security, you're missing a crucial component of a working system which wasn't important to the explanation but is crucial to a working system.
My experience over and over in life is that I read about something complex, think I understand it, go try to do it, eg, writing a proof or code or teaching it to someone else, and discover that there were some aspects of the thing that I didn't fully understand or had a misconception about. That observation that even very smart people are good at convincing themselves they understand something better than they actually do is basically why the Feynman Technique works so well. I tend to just like to write toy programs and simulations to check my understanding. The resulting prose or program isn't the point, it's all the points you hit in the process where you realize you're missing something. I write small prototypes pretty much every day, learn from them, throw them away, then apply what I learned on the real problem I'm working on. I find that to be an incredibly fruitful approach.
I coded up a toy RSA implementation after we had a lecture about RSA in my Number Theory class. And I didn't say that it didn't work; it just obviously didn't perform very well because that wasn't the point (I was very new to programming and working in JS as that was the only environment available to me). I'm sorry I can't pinpoint the exact details of what I learned about RSA a quarter century ago. When I took a Cryptography class a couple years later taught by Michael Rabin, I did very well and felt like I had a better grasp of some of the basic ideas than I would've if I hadn't spent some time working through some basic implementations.
The OP's code needed a little help; there were some missing functions, misnamed calls, and he didn't use js BigInts (which are built-in to the browser, and you can use them as literals by appending 'n' to a number.)
See (and run) the fixed up code here: https://simpatico.io/crypto.md#rsafromscratch
EDIT: for my own crypto needs in the browser I use `subtle.crypto` with ECDH - https://en.wikipedia.org/wiki/Elliptic-curve_Diffie%E2%80%93...
I prefer to zoom out and realize that everyone wants all tutorials to be written in their favorite language, and realizing this makes me a little less attached to mine, and more accepting of others, even if they are not for me.
Many learn, that recursion is something dangerous for example, because their learning vehicle language has no good implementation for it. Another example is memory allocation. You wouldn't teach that in Python probably. Or a concept like ownership, which would be good to teach in Rust, where the language has that concept explicitly and visibly built into it.
Never use textbook RSA.
Source: every course on cryptography.