Daniel J. Bernstein:

No. What's implemented is Shoup's "Simple RSA", aka "RSA-KEM". The session key is a hash of a fully random plaintext as long as the modulus.


Thomas H. Ptacek:

Scott Arciszewski:

Will Post-Quantum RSA still be accompanied by PKCS1v1.5 padding?