New RSA attack breaks signatures without factoring the key
Researchers at UCSD described a signature-forgery attack on RSA using a "special" number field sieve that avoids factoring the key. Security of 1024-, 2048- and 4096-bit keys drops to 2^65, 2^90 and 2^119 operations. Only blind-signature implementations, including Privacy Pass used by Apple and Cloudflare, are affected.
- Attack cuts 1024-bit RSA security to 2^65 operations and 1,380 core-years
- 2048- and 4096-bit keys drop to 2^90 and 2^119 respectively
- Only blind-signature RSA is vulnerable, including Privacy Pass
- No AI or GPUs were used, so security levels may drop further
Read next
Security