To protect against bleichbacher attackers. Probably modeled on https://golang.org/pkg/crypto/rsa/#DecryptPKCS1v15SessionKey