Researchers Devise Signature-Forgery Attack That Weakens RSA Without Factoring Keys
A team including UC San Diego professor Nadia Heninger published research describing a new classical-computing attack that forges RSA signatures without factoring the underlying keys. The method reportedly cracked deprecated 1024-bit RSA keys in a few months using an academic CPU cluster, far less effort than factoring would require, and it also degrades the theoretical security of 2048- and 4096-bit keys.
GoKawiil's interpretation of the reporting above, not reported fact.
The findings suggest a previously unrecognized gap in the assumption that breaking RSA signatures is as hard as factoring large integers, which cryptographer Karsten Nohl called a possible 'conceptual break-through' if confirmed by peer review. Heninger argues the result strengthens the case for migrating away from RSA during the ongoing shift to post-quantum cryptography, though currently deployed RSA implementations at standard key sizes remain safe for now.
- A new attack forges RSA signatures without factoring keys, using only classical computing.
- 1024-bit RSA keys were broken in months on an academic cluster, far faster than factoring would allow.
- The attack also lowers effective security margins for 2048- and 4096-bit RSA, fueling calls to move beyond RSA.
Source: it.slashdot.org — Posted, 2026-09-25
Published there as: “There's a New Way to Break RSA Encryption”
Read the original report → The summary and analysis above are GoKawiil's own, written from reporting by the source above. Facts and quotes belong to the original publisher.