The flaw of textbook RSA
MCQAn attacker intercepts several "raw" RSA ciphertexts (without padding) from a voting system where each ballot is worth "YES" or "NO". Without ever knowing the private key, they manage to find out who voted what. Which flaw of textbook RSA do they exploit first?

