There's a new way to break RSA that's faster than anything we've seen before
The attack cuts estimated security for textbook RSA and could help forge signatures with far fewer operations, researchers said.
- Researchers implemented a variant of the "special" number field sieve to forge signatures on "textbook" RSA encryption, revealing a previously unknown weakness in blind-signature implementations that bypasses traditional factoring requirements.
- The technique targets an "oracle," a weakness in RSA that provides yes-or-no answers to specific queries, allowing attackers to forge signatures without factoring the large integers typically required to break encryption.
- Researchers broke encryption using an academic CPU cluster that dedicated 1,380 CPU core-years to the problem over five months, drastically lowering security levels for 1024-, 2048-, and 4096-bit keys.
- UC San Diego professor Nadia Heninger noted the attack affects implementations like Privacy Pass, used by Apple and Cloudflare; compromising such a server would require generating 243 signatures to forge a token.
- The NIST plans to deprecate RSA by 2030, and cryptographers are working to devise alternative systems. Heninger said these specialized tools will "almost certainly" drop the security levels further.
18 Articles
18 Articles
Researchers forged RSA signatures without ever cracking the key
The technique is practical against 1,024-bit RSA keys, which are already deprecated. It also lowers the estimated security of 2,048-bit and 4,096-bit keys when they are used in vulnerable blind-signature systems.Read Entire Article
RSA Forgery Without Factoring: Researchers Slash Security of 1024-Bit Keys
UC San Diego and INRIA researchers forged 1024-bit RSA signatures without factoring the key, using an oracle and special number field sieve variant. The attack took 1,380 core-years versus 500,000+ for factoring. It affects only raw or blind RSA schemes, not padded implementations. Standards bodies should revisit security estimates for systems with signing oracles.
Researchers from the University of California in San Diego and the Inria Nancy have just struck a severe blow to global asymmetric encryption. Their unprecedented method completely bypasses the historical mathematical obstacle of factorization of large integers. They thus directly compromise the 1024 bit keys. What to upset the absolute certitudes of the community ... Read more The article A major conceptual flaw shakes the foundations of RSA en…
New Attack Against RSA - Schneier on Security
ArsTechnica is reporting on a “new” attack against RSA, one that bypasses factoring. First, this attack isn’t new. The original research is from 2007. What is new is the implementation. Second, it is a forgery attack. It allows an attacker to forge digital signatures. It does not recover the private key from the public key. Third, the attack only works against pure signatures. That is, signatures without any formatting or padding. This is not ge…
Coverage Details
Bias Distribution
- 75% of the sources are Center
Factuality
To view factuality data please Upgrade to Premium















