Until now, cryptographers thought factoring was the only way to break RSA. Not anymore.
2 comments
> The algorithm only works if a raw signing oracle is available. Most RSA usage in practice (that is, RSA signatures using PKCS#1v1.5 or RSA-PSS padding) do not expose such an oracle, and thus this attack does not pose a practical risk. Examples of RSA use that do expose such a signing oracle would include blind RSA signatures (e.g. Privacy Pass) or HSM APIs.
> Are people actually still using RSA?
> Yes, particularly for digital signatures (e.g. certificates, TLS handshakes, tokens, OAuth). Key exchange for protocols like TLS uses ECDH or has transitioned to ML-KEM, and the attack does not apply to these algorithms.
This is breaking only some rare kinds of RSA usage... And if you are considering new system that uses RSA signatures, please don't. Use elliptic curves - the operations are faster, the signatures and keys are smaller, and there are fewer attacks.
Even PrivacyPass stopped using RSA signatures for that reason [0], which means that the only example of applicable technology is no longer correct.
[0] https://blog.cloudflare.com/privacy-pass-the-math/#previousl...
Read the full thread on Hacker News →
Related stories
- Ars Technica · 0 points · 7 days ago
- Hacker News · 4 points · 5 days ago
- Hacker News · 1 points · 4 days ago
- Hacker News · 4 points · 6 days ago
- Lobsters · 1 points · 6 days ago
- Forging 1024-bit RSA signatures in nearly SNFS timeeprint.iacr.orgLobsters · 7 points · 6 days ago