Question, how would it be vulnerable to a man in the middle attack? Even though torque commands aren't encrypted they're only sent directly to the server. (Which could theoretically be spied on with a packet sniffer, but really nothing other than that)
If someone is impersonating the host from the beginning, then all is lost tbh.
It WOULD however be vulnerable to someone who say, has access to your server through the rtb control panel or one of the many remote control admin mods out there. Though that's really unavoidable.
no because they don't know the full data they only know theirs and any cohorts
Unless we decide to use twice the data, that would mean they have to guess half of the plaintext that would have had to guess in order to get the keys.
Or less. Depends.