New Attack Against RSA
BLUF
This RSA signature forgery vulnerability is largely theoretical for modern implementations using proper padding.
NEWS
ArsTechnica reported a new RSA attack bypassing factoring, but Schneier notes the underlying research dates to 2007. The exploit allows signature forgery on pure RSA without padding, not private key recovery. Performance remains subexponential rather than polynomial time.
Why I Care
Organizations relying on legacy or custom cryptographic implementations using raw RSA signatures face potential forgery risks. However, standard TLS/SSL and PGP systems using padded RSA remain secure from this specific vector.
Next Steps
Audit cryptographic libraries to ensure PKCS#1 v1.5 or PSS padding is enforced on all RSA signature operations. No immediate patching is required for standard protocols, but legacy systems should be reviewed immediately.
Source: Schneier on Security ·