Researchers forged RSA signatures without cracking the key
Researchers found a way to forge certain RSA signatures without factoring the private key, using a variant of the special number field sieve and an oracle in blind-signature protocols. The attack is practical against 1024-bit keys (about 2^65 operations and 1,380 CPU core-years) and lowers the estimated security of 2048- and 4096-bit keys to 2^90 and 2^119. Most RSA deployments using PKCS or PSS padding are not affected.
- Attack forges signatures without factoring the key, relying on an oracle in blind signatures
- 1024-bit RSA: about 2^65 operations and 1,380 CPU core-years on a cluster
- Estimated security of 2048- and 4096-bit keys drops to 2^90 and 2^119
- Only blind-signature systems like Privacy Pass are vulnerable
Read next
Security