21 comments
tptacek6 days ago
The most important thing to know about this work, which is awesome, is that it relies on access to a raw RSA oracle, where you have a public key and an API that allows you to directly do RSA operations with the corresponding key. The idea is that you then lose access to the oracle, and thus to the private key, but you've gained enough information from your session with the oracle to make forgeries in the future.
So it's not a straightforward general-purpose RSA-1024 signature break; it's pretty situational. The paper goes into detail (in section 5) about how those situations can emerge in practical scenarios.
deprave6 days ago
It’s important to note that by “raw” they mean without padding, which is more rare than just a signing oracle, see section 7 of the paper.
bflesch6 days ago
Thank you for this nice explanation. I skimmed the abstract but didn't really understand it.
hn_submit6 days ago
All these articles are merely clickbait. I knew there wasn't a real break in RSA before reading the article. It's just some weird subset of usage which allows this. It's nowhere near breaking RSA.
Why are we even contemplating quantum computers breaking encryption when they can't even factorize a 3-digit prime number? I'm wondering if I'll even see quantum computers breaking RSA in my lifetime.
tptacek6 days ago
I'm pretty sure you just described an IACR paper --- with Nadia Heninger's name on it --- as "clickbait"?
yababa_y6 days ago
in the PDF metadata we find the proper and appropriate title of this work:
Nearly SNFS-Speed Signature Forgery Sans Factoring N (NSNFSSSFSFN)RossBencina6 days ago
I was expecting to see mention of Microsoft/Apple executable code-signing in the examples. I know key lengths are well beyond 1024 now, but on the Microsoft side it was (is?) possible for USB tokens to be distributed in the mail. What I don't know is whether the tokens could be used as oracles in this attack.
nk_kolja6 days ago
I was unaware of snfs algorithms for generic moduli and/or signatures. Very nice.
The theoretical result is purely due to the 2007 Joux et al. paper.
What’s new is the implementation and the 1024-bit rsa signature forgery.
Also no ai, so we can expect some speedups soon.
I really didn’t expect rsa to be targeted so much this year. Hope that these results will motivate people to pursue algorithmic improvements!
Galois123454 days ago
Actually it does apply to some padding schemes but old ones those based on the adding of a fixed pattern of bits.
Read the full thread on Hacker News →
Related stories
- Forging 1024-bit RSA signatures in nearly SNFS timeeprint.iacr.orgLobsters · 7 points · 7 days ago
- Hacker News · 1 points · 2 days ago
- Hacker News · 421 points · 6 days ago
- Hacker News · 3 points · 3 days ago
- Hacker News · 1 points · 6 days ago
- Hacker News · 1 points · 4 days ago