Urgent.News

What's breaking now, across thousands of outlets.

Tech

There's a New Way to Break RSA Encryption

"Signature forgery." It's a new way to break RSA keys — and it doesn't require factoring. Ars Technica reports on new research using classical computing to "reduce the current RSA security level to an unacceptably low threshold" and lower the required computing resources by orders of magnitude. There's "a gap in current RSA-type security assumptions," according to a paper co-authored by…

Breaking RSA encryption has a new method, which doesn't require factoring. A recent study by researchers from the University of California, San Diego claims this approach could dramatically reduce the security of RSA keys. The study, co-authored by Nadia Heninger, reveals a significant gap in RSA-type security assumptions, suggesting a shift away from RSA during the post-quantum transition.

Although the practical risk is limited, it still warrants attention. Applying this attack to deprecated 1024-bit keys took a few months on an academic CPU cluster, which is far less than the time required for 1024-bit factoring using massive resources. Widely-used RSA implementations remain secure, but the findings have caught cryptographers off guard.

If validated, this would be a significant breakthrough, as RSA's difficulty lies in factoring large integers, not key forging. The researchers' blind-signature implementation attack could practically break RSA without cracking its key. For 1024-, 2048-, and 4096-bit keys, this method reduces security to 2**65, 2**90, and 2**119 bits, respectively.

These levels are likely to decrease further as the researchers used no AI or GPUs in their forgeries. The attack targets blind-signature RSA implementations only. Despite the relatively small real-world threat, the new attack lowers the estimated security of textbook RSA and underscores the need for a complete move away from the cryptosystem.

Written by urgent.news from Slashdot's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at it.slashdot.org →

More in Tech

More from Friday 25 September →