Why RSA encryption padding is critical (cool RSA implementation flaw)
rdist.root.org
rdist.root.org
This is really just reason number 242151205 why you shouldn't attempt to build your own crypto system.
No, it's reason 242151205 why you should read the established standards. RFC 3447 says "use RSA-OAEP for encryption and RSA-PSS for signing".
If you have security flaws due to doing something non-standard in any field other than cryptography, people will say you're an idiot. Why does cryptography get a free pass with "oh well, we all know that stuff's hard"?
http://citeseerx.ist.psu.edu/viewdoc/summary?doi=10.1.1.33.6...
http://media.ccc.de/browse/congress/2008/25c3-2799-en-consol...
*edit: it's about Team Tweezer exploiting the RSA implementation on nintendo's Wii to run unsigned code.