

So for RSA without padding, a threat actor could request lots of tokens (without getting rate-limited?), and use that as information to more precisely focus efforts to brute-force the key, and thereby reducing the number of operations required to do so? Or am I misunderstanding it?



Western governments should look in the mirror, instead of solely putting the blame at information-campaigns from foreign actors. The whole reason why these theories seem plausible to your own citizens, is because they have no faith in you; because you have a track record of acting against their best interests. An increasing number of people are sick of hearing one-sided, fearmongering, and escalating narratives, where anything that challenges that, be it truthful or not, may resonate with this group. And good luck discerning disinformation from misinformation, where the only difference is intent; which will be challenging to substantiate.