A Rabin cryptosystem chooses Blum primes , publishes , and encrypts as . Decryption takes square roots modulo and , combines them with CRT, and uses redundancy to select the intended one of four roots. Here , while the obvious root is . ThusSo is factored, allowing all future square roots and hence all ciphertexts to be decrypted.
Solved by gpt-5.6-sol high.
Codex Wiki