News: 0185852327

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

There's a New Way to Break RSA Encryption (arstechnica.com)

(Friday September 25, 2026 @10:34PM (EditorDavid) from the key-holes dept.)


" [1]Signature forgery ." It's a new way to break RSA keys — and it doesn't require factoring. [2] Ars Technica reports on new research using classical computing to "reduce the current RSA security level to an unacceptably low threshold" and lower the required computing resources by orders of magnitude.

There's "a gap in current RSA-type security assumptions," according to [3]a paper co-authored by University of California, San Diego professor Nadia Heninger, who argues that gap "gives classical cryptanalytic evidence in favor of moving away from RSA entirely during the current post-quantum transition."

> The practical risk is limited, but still significant. Applying the attack against the deprecated use of 1024-bit keys took a handful of months on an academic CPU cluster, significantly less than the current estimates for 1024-bit factoring that would require resources that only nations or companies with massive resources could achieve. Widely used RSA implementations are also safe. Nonetheless, the research has taken cryptographers by surprise... "If this result holds up under peer review, it would indeed be a conceptual break-through," Karsten Nohl, a cryptography expert and the head of innovation at Allurity, said in an interview. "RSA is as difficult to break as it is to factor large integers, at least so we thought. The researcher suggests that you can practically break RSA without cracking its key...."

>

> The key forgery attack Heninger and the other researchers devised poses an immediate threat to 1024-bit RSA. Even for 2048- and 4096-bit keys, the method reduces the security of RSA to unacceptable levels. The National Security Agency, [4]National Institute of Standards and Technology , and [5]European Union Agency for Network and Information Security require that any cryptosystem should provide a level of no less than 128 or more bits, meaning the operations required must exceed 2**128. The forgery attack drops these levels to 2**65, 2**90, and 2**119 for 1024-, 2048-, and 4096-bit keys respectively. These levels may further drop because Heninger's team did all the coding by hand and used no AI or GPUs in performing the forgeries. The researcher said these tools will "almost certainly" drop the security levels further.

>

> The attack works only against [6]blind-signature implementations of RSA... Still, some real-world systems continue to use blind-signature, also known as textbook, RSA... The paper's authors and other researchers stress that the new attack poses little real-world threat. It does, however, drastically lower the estimated security of textbook RSA, and it does so in a way no one knew of previously... The new attack will further increase the urgency of completely moving away from the cryptosystem.

Thanks to long-time Slashdot reader [7]phatrabt for sharing the article.



[1] https://github.com/ucsd-hacc/NSNFSSSFSFN

[2] https://arstechnica.com/security/2026/09/theres-a-new-way-to-break-rsa-thats-faster-than-anything-weve-seen-before/

[3] https://eprint.iacr.org/2026/2131.pdf

[4] https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-57pt1r5.pdf

[5] https://web.archive.org/web/20151017094652/https://www.enisa.europa.eu/activities/identity-and-trust/library/deliverables/algorithms-key-size-and-parameters-report-2014/at_download/fullReport

[6] https://www.ietf.org/archive/id/draft-irtf-cfrg-rsa-blind-signatures-02.html

[7] https://www.slashdot.org/~phatrabt



Wat (Score:3)

by drinkypoo ( 153816 )

"post-quantum transition"

At this point it's impossible to tell whether I'm done laughing or not.

Re: (Score:2)

by wickerprints ( 1094741 )

Please do let us in on the joke and share your explanation of what you find so funny about this phrase.

Re: (Score:1)

by unfriendlyLLM ( 10459763 )

This works without quantum computers and you don't even have to actually crack the key to implement it. This suggests that not the key but the implementation is flawed. So we fail fundamental logic tests. So, we are running downhill into the future with no idea what we are doing.

Re: (Score:1)

by unfriendlyLLM ( 10459763 )

I went to public school pay me no nevermind. "Make America Great Again" and all that.

Time to cascade algorithms... (Score:2)

by ctilsie242 ( 4841247 )

I'm beginning to think we need to do like VeraCrypt does as an option. Three algorithms. One optimized against QC, and two proven, solid ones that are somewhat resistant to that. Yes, it means three times the CPU to validate/sign the same stuff, but it protects us against catastrophic algorithm failure where one discover might reduce a keyspace to something trivial.

Downside of doing this is that some dedicated cryptographic processors have their die designed around the mathematical functions of that spec

Multi algorithm leads to multi core ? (Score:1)

by drnb ( 2434720 )

> Yes, it means three times the CPU to validate/sign the same stuff ...

That's OK, most will have 3x or more the number of CPU cores than when VeraCrypt first came out. :-)

> Downside of doing this is that some dedicated cryptographic processors have their die designed around the mathematical functions of that specific algorithm, and it can get expensive to design for multiples.

If we are talking dedicated crypto processors, we could have different cores with different algorithms? It's already common to have different types of cores in a single CPU, high performance and power efficiency for example.

Re: (Score:2)

by martin-boundary ( 547041 )

If you do, millions of cats will spontaneously decrement their 9 lives counters!

OK... (Score:4, Interesting)

by 0123456 ( 636235 )

I don't really care enough about RSA to read deeply into the paper, but it seems to exploit a service that will sign billions of your messages with the secret key that you are trying to crack... which I seem to recall was known to be a potential problem for RSA thirty years ago (so don't do that).

Re: OK... (Score:3)

by fluffernutter ( 1411889 )

i know the Python cryptography libraries specifically warn not to do that for years now. this is a known problem.

Re: (Score:2)

by arglebargle_xiv ( 2212710 )

It exploits a misuse of RSA that virtually nothing in existence does. When the various standards for RSA were created decades ago, PKCS #1, X9.31, ISO 9796, and so on, they were specifically designed to prevent this type of attack. So it's academically reasonably interesting, but otherwise nothing to worry about unless.

Not new, but ... (Score:5, Funny)

by fahrbot-bot ( 874524 )

> It's a new way to break RSA keys — and it doesn't require factoring.

[1]Obviously [xkcd.com] ... :-)

[1] https://xkcd.com/538/

Re: (Score:2)

by rsilvergun ( 571051 )

They hacked right through my ROT 26 encryption!

sigh (Score:2)

by XaXXon ( 202882 )

> These levels may further drop because Heninger's team did all the coding by hand and used no AI or GPUs in performing the forgeries.

Using a GPU doesn't change the number of bits of useful encryption you have. Whoever wrote this has no understanding of what they're talking about.

Re: (Score:2)

by XaXXon ( 202882 )

Dan Goodin

Senior Security Editor

Lulz @ ars. Hard to get good help these days, I guess.

Re: (Score:1)

by unfriendlyLLM ( 10459763 )

>> These levels may further drop because Heninger's team did all the coding by hand and used no AI or GPUs in performing the forgeries.

> Using a GPU doesn't change the number of bits of useful encryption you have. Whoever wrote this has no understanding of what they're talking about.

But i am worried that it will affect where in I/O a privileged application can even attempt it.

Let me get this straight (Score:2)

by WaffleMonster ( 969671 )

There is no practical exploit even if the method were applicable which it is not.

Hermes 2 Malware (Score:2)

by Khyber ( 864651 )

2048-bit RSA that protects an AES-256 key that actually does the encryption - those of you that ever had a ransomware hit you from a cock.li address might have hope of recovering your stuff, yet!

I don't wanna argue, and I don't wanna fight,
But there will definitely be a party tonight...