Forgot your password?
typodupeerror
Encryption

There's a New Way to Break RSA Encryption (arstechnica.com) 48

"Signature forgery." It's a new way to break RSA keys — and it doesn't require factoring. Ars Technica reports on new research using classical computing to "reduce the current RSA security level to an unacceptably low threshold" and lower the required computing resources by orders of magnitude.

There's "a gap in current RSA-type security assumptions," according to a paper co-authored by University of California, San Diego professor Nadia Heninger, who argues that gap "gives classical cryptanalytic evidence in favor of moving away from RSA entirely during the current post-quantum transition." The practical risk is limited, but still significant. Applying the attack against the deprecated use of 1024-bit keys took a handful of months on an academic CPU cluster, significantly less than the current estimates for 1024-bit factoring that would require resources that only nations or companies with massive resources could achieve. Widely used RSA implementations are also safe. Nonetheless, the research has taken cryptographers by surprise... "If this result holds up under peer review, it would indeed be a conceptual break-through," Karsten Nohl, a cryptography expert and the head of innovation at Allurity, said in an interview. "RSA is as difficult to break as it is to factor large integers, at least so we thought. The researcher suggests that you can practically break RSA without cracking its key...."

The key forgery attack Heninger and the other researchers devised poses an immediate threat to 1024-bit RSA. Even for 2048- and 4096-bit keys, the method reduces the security of RSA to unacceptable levels. The National Security Agency, National Institute of Standards and Technology, and European Union Agency for Network and Information Security require that any cryptosystem should provide a level of no less than 128 or more bits, meaning the operations required must exceed 2**128. The forgery attack drops these levels to 2**65, 2**90, and 2**119 for 1024-, 2048-, and 4096-bit keys respectively. These levels may further drop because Heninger's team did all the coding by hand and used no AI or GPUs in performing the forgeries. The researcher said these tools will "almost certainly" drop the security levels further.

The attack works only against blind-signature implementations of RSA... Still, some real-world systems continue to use blind-signature, also known as textbook, RSA... The paper's authors and other researchers stress that the new attack poses little real-world threat. It does, however, drastically lower the estimated security of textbook RSA, and it does so in a way no one knew of previously... The new attack will further increase the urgency of completely moving away from the cryptosystem.

Thanks to long-time Slashdot reader phatrabt for sharing the article.

There's a New Way to Break RSA Encryption

Comments Filter:
  • Wat (Score:5, Funny)

    by drinkypoo ( 153816 ) <drink@hyperlogos.org> on Friday September 25, 2026 @07:18PM (#66350996) Homepage Journal

    "post-quantum transition"

    At this point it's impossible to tell whether I'm done laughing or not.

    • Please do let us in on the joke and share your explanation of what you find so funny about this phrase.

      • Re:Wat (Score:4, Interesting)

        by Junta ( 36770 ) on Saturday September 26, 2026 @03:09AM (#66351142)

        Well, to me it's funny to hitch this finding to post quantum as it is a totally orthogonal concern.

        Along with saying RSA is *totally* useless because a rather niche application of it has an evident weakness, that is not claimed to be more generally applicable.

        They may have an interesting and important finding, but are stirring up a bigger mess than is warranted by implying a broader impact to anything using RSA.

        If you weren't considering migration from RSA an urgent issue before, this changes nothing.

      • He is old, he is not keeping track on what is going on in the word.

        Every majour company is working on transition to quantum decryption save algorithms.

        Just go to a random software conference and there will be plenty of talks about that.

        • He is old, he is not keeping track on what is going on in the word.

          I'm keeping more track as I age, not less. Perhaps your capabilities have diminished further than mine? I was pretty young when I signed up, it would be surprising if you were younger than I am.

          Every majour company is working on transition to quantum decryption save algorithms.

          Every competent major company has done it already, but they didn't do it because quantum computing was here, they did it because it might come someday and they wanted cryptosystems which were proof against the potential vulnerability.

          Just go to a random software conference and there will be plenty of talks about that.

          Yes, from people selling shit to suckers. But since there are no practical quantum c

    • I'm beginning to think we need to do like VeraCrypt does as an option. Three algorithms. One optimized against QC, and two proven, solid ones that are somewhat resistant to that. Yes, it means three times the CPU to validate/sign the same stuff, but it protects us against catastrophic algorithm failure where one discover might reduce a keyspace to something trivial.

      Downside of doing this is that some dedicated cryptographic processors have their die designed around the mathematical functions of that spec

      • Yes, it means three times the CPU to validate/sign the same stuff ...

        That's OK, most will have 3x or more the number of CPU cores than when VeraCrypt first came out. :-)

        Downside of doing this is that some dedicated cryptographic processors have their die designed around the mathematical functions of that specific algorithm, and it can get expensive to design for multiples.

        If we are talking dedicated crypto processors, we could have different cores with different algorithms? It's already common to have different types of cores in a single CPU, high performance and power efficiency for example.

    • If you do, millions of cats will spontaneously decrement their 9 lives counters!
    • So its Schrodinger's laugh?

    • by BenBoy ( 615230 )
      That suggests you might be in a superposition of laughter and non-laughter ... iirc the only way to tell is to open your box.
    • by kriston ( 7886 )

      Haven't we all moved to Ed25519 years ago, though?

      • by eric76 ( 679787 )

        Haven't we all moved to Ed25519 years ago, though?

        On my servers, I require three separate ssh keys to log in: AuthenticationMethods publickey,publickey,publickey. Logging in with passwords is not permitted over ssh, but that's not a big deal since any account with a password is blocked from logging in via ssh. If the account has a password, it is intended for logging in at the console only. They also permit S/KEY from the console. Also for the RSA key, at least 4096 bits is required: RequiredRSAsize 4096

    • post quantum is funny and not funny at the same time its impossible to know which one.

    • by sjames ( 1099 )

      You are both done laughing and not done laughing.

  • OK... (Score:5, Interesting)

    by 0123456 ( 636235 ) on Friday September 25, 2026 @07:31PM (#66351010)

    I don't really care enough about RSA to read deeply into the paper, but it seems to exploit a service that will sign billions of your messages with the secret key that you are trying to crack... which I seem to recall was known to be a potential problem for RSA thirty years ago (so don't do that).

  • by fahrbot-bot ( 874524 ) on Friday September 25, 2026 @07:39PM (#66351018)

    It's a new way to break RSA keys — and it doesn't require factoring.

    Obviously [xkcd.com] ... :-)

  • by XaXXon ( 202882 )

    > These levels may further drop because Heninger's team did all the coding by hand and used no AI or GPUs in performing the forgeries.

    Using a GPU doesn't change the number of bits of useful encryption you have. Whoever wrote this has no understanding of what they're talking about.

    • by XaXXon ( 202882 )

      > Dan Goodin
      > Senior Security Editor

      Lulz @ ars. Hard to get good help these days, I guess.

    • > These levels may further drop because Heninger's team did all the coding by hand and used no AI or GPUs in performing the forgeries.

      Using a GPU doesn't change the number of bits of useful encryption you have. Whoever wrote this has no understanding of what they're talking about.

      But i am worried that it will affect where in I/O a privileged application can even attempt it.

    • Re:sigh (Score:4, Informative)

      by Khyber ( 864651 ) <techkitsune@gmail.com> on Saturday September 26, 2026 @12:21AM (#66351112) Homepage Journal

      Using a GPU versus a CPU (as was done here) increases how quickly you can churn through those remaining possible permutations (I read the actual paper.)

      What was done on an academic CPU cluster could probably be just as easily performed on a well-tuned bitcoin rig at far far faster speed.

  • by WaffleMonster ( 969671 ) on Friday September 25, 2026 @08:06PM (#66351026)

    There is no practical exploit even if the method were applicable which it is not.

  • 2048-bit RSA that protects an AES-256 key that actually does the encryption - those of you that ever had a ransomware hit you from a cock.li address might have hope of recovering your stuff, yet!

  • The new attack will further increase the urgency of completely moving away from the cryptosystem.

    Depends on what they mean by "the" cryptosystem. If they mean use of RSA in general, then not really, it narrowly only applies to a specific application of RSA allowing an authority to sign something without actually seeing the something, which almost never is done. It sounds like it does not speak to RSA more broadly.

  • If you do the numbers, you see that with the new method you'd need about 80% as many attempts as before. That's still much.

  • Can I now recover my lost password for my Bitcoin wallet?

  • This attack requires the combination of two things
    1) the attacker is, at some point, in position to obtain RSA signature or decryption at will using the key under attack
    2) and during this phase it is not enforced the use of a padding scheme, like RSASSA-PKCS1-v1_5, RSASSA-PSS, ISO/IEC 9796-2, RSAES-PKCS1-v1_5, RSAES-OAEP
    Assuming this, the attack allows the adversary to obtain the private key.

    The main case I see this is meaningful is if an adversary gains temporary and direct access to a signing or decrypti

    • by fgrieu ( 596228 )

      uh, forget everything I wrote after "the attack allows". The attack does not allow key extraction. It allows to obtain a signature that was not obtained thru the oracle, in a new way.

If you think the system is working, ask someone who's waiting for a prompt.

Working...