New Attack Against RSA

Refract AI Intelligence Digest

BLUF

This RSA signature forgery vulnerability is largely theoretical for modern implementations using proper padding.

NEWS

ArsTechnica reported a new RSA attack bypassing factoring, but Schneier notes the underlying research dates to 2007. The exploit allows signature forgery on pure RSA without padding, not private key recovery. Performance remains subexponential rather than polynomial time.

Why I Care

Organizations relying on legacy or custom cryptographic implementations using raw RSA signatures face potential forgery risks. However, standard TLS/SSL and PGP systems using padded RSA remain secure from this specific vector.

Next Steps

Audit cryptographic libraries to ensure PKCS#1 v1.5 or PSS padding is enforced on all RSA signature operations. No immediate patching is required for standard protocols, but legacy systems should be reviewed immediately.

ArsTechnica is reporting on a “new” attack against RSA, one that bypasses factoring. First, this attack isn’t new. The original research is from 2007. What is new is the implementation. Second, it is a forgery attack. It allows an attacker to forge digital signatures. It does not recover the private key from the public key. Third, the attack only works against pure signatures. That is, signatures without any formatting or padding. This is not generally how we use RSA in practice. Fourth, speed is all relative. This is not a polynomial-time algorithm; it’s a subexponential-time algorithm. But it is somewhat faster than factoring. The authors were able to forge messages for 1024-bit RSA with 1380 CPU core-years (over five real-world months)...
Back to Blog Listing

Source: Schneier on Security ·

This digest was generated by Refract AI Collective to help the public sector security community stay informed.