Skip to main content
CybersecurityHacking

RSA Factoring Attack Evolves Into Faster Forgery Method

Mathematician's workspace with laptop, notes, and technical books in natural daylight.

1380 CPU core‑years — the computing effort the paper’s authors report using to forge signatures on a 1024‑bit RSA key over “over five real‑world months.”

What the attack actually achieves

The published implementation is a forgery attack: it produces valid digital signatures without extracting the private key from the public key. The research does not claim, and the reporting does not show, any recovery of RSA private keys — the technique is entirely about producing forged signatures rather than breaking a keypair.

Scope and constraints: “pure signatures” only

Crucially, the method applies to so‑called pure signatures — signatures created with RSA and no formatting or padding. The authors and subsequent commentary emphasize that the attack does not work against signatures that include standard formatting or padding schemes. As the summary puts it, this is “not generally how we use RSA in practice,” a point that confines the technique to a narrow class of vulnerable implementations.

Complexity and practical cost: subexponential, somewhat faster than factoring

Technically, the algorithm is subexponential rather than polynomial time. The authors describe it as somewhat faster than factoring, but still computationally expensive in absolute terms. Their implementation forged messages for 1024‑bit RSA at a measured cost of 1380 CPU core‑years, which they equate to a little over five months of calendar time in their experimental setup. That combination — subexponential complexity and very large resource needs — places the attack in a gray area between theoretical novelty and practical exploitability.

Origins and the contribution of a new implementation

The underlying research dates back to 2007; what is new in this announcement is the availability of an implemented attack. The authors have published a webpage that explains the context and have released a paper documenting their work. Public discussion has followed in forums such as a Slashdot thread. Media outlets have framed the recently publicized implementation as a “new” attack against RSA, though the foundational technique itself is older.

How cryptographic implementers, standards bodies, and end users are likely to react

  • Cryptographic implementers and security teams: They will examine whether any deployed code performs RSA signing without padding or formatting; pure‑signature implementations are the explicit target described by the authors.
  • Standards bodies and procurement officers: Given that the attack targets non‑padded signatures, standards and acquisition requirements that mandate padding or formatted signature schemes will see renewed justification in practice.
  • End users and application owners: For most applications that use standard RSA padding or formatting, the published work narrows the immediate practical exposure to a specific implementation pattern rather than to RSA as broadly deployed.

The paper and its implementation sharpen a narrow but real distinction: an older mathematical technique, when instantiated in modern code, can move from theoretical footnote to demonstrable capability — at measurable cost. The reported experiment shows that forging 1024‑bit pure RSA signatures is feasible given significant compute resources, but because the attack does not recover private keys and targets unpadded signatures, its practical impact depends directly on whether systems still produce pure RSA signatures in the wild.

Read the original post

RSA Factoring Attack Evolves Into Faster Forgery Method | OSINTSights