New RSA signature attack cuts the cost of breaking unpadded keys
The classical-computing technique is a conceptual breakthrough, but common PKCS and PSS implementations are not vulnerable.
TLDR
Researchers led by UC San Diego professor Nadia Heninger have demonstrated a new way to forge signatures from textbook, or blind-signature, RSA without factoring the private key, Ars Technica reports. Their special number-field-sieve attack lowers estimated work from 2^80 to 2^65 operations for a 1,024-bit key and reduces the theoretical security of larger keys as well. The result is significant for cryptography, but it is not an immediate internet-wide emergency: common RSA implementations use PKCS or PSS padding, which blocks the required oracle, and even the 1,024-bit attack still demands enormous computing resources.
New RSA signature attack cuts the cost of breaking unpadded keys
The classical-computing technique is a conceptual breakthrough, but common PKCS and PSS implementations are not vulnerable.
TLDR
Researchers led by UC San Diego professor Nadia Heninger have demonstrated a new way to forge signatures from textbook, or blind-signature, RSA without factoring the private key, Ars Technica reports. Their special number-field-sieve attack lowers estimated work from 2^80 to 2^65 operations for a 1,024-bit key and reduces the theoretical security of larger keys as well. The result is significant for cryptography, but it is not an immediate internet-wide emergency: common RSA implementations use PKCS or PSS padding, which blocks the required oracle, and even the 1,024-bit attack still demands enormous computing resources.
