ABSTRACT

In this chapter, we illustrate the dangers of using RSA with a small private exponent. While it may be desirable in some situations to decrease decryption costs as much as possible there are, as will be demonstrated, very practical attacks that can render the system completely insecure if the private exponent is chosen too small.