Close Menu
AI News TodayAI News Today

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Towards Spec-Driven Test Automation: Part 1

    YouTube Music gets more conversational with new AI features

    An OpenAI Agent Hacked Australia’s Health Service. Their Government Found Out Months Later

    Facebook X (Twitter) Instagram
    • About Us
    • Contact Us
    Facebook X (Twitter) Instagram Pinterest Vimeo
    AI News TodayAI News Today
    • Home
    • AI News
    • AI Reviews
    • AI Tools
    • AI Tutorials
    • Chatbots
    • Free AI Tools
    • Artificial Intelligence
    AI News TodayAI News Today
    Home»Chatbots»There’s a new way to break RSA that’s faster than anything we’ve seen before
    Chatbots

    There’s a new way to break RSA that’s faster than anything we’ve seen before

    By No Comments3 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    A transparent digital chain breaking at its weakest point over a binary code background.
    Share
    Facebook Twitter LinkedIn Pinterest Email

    The forgery attack drops these levels to 265, 290, and 2119 for 1024-, 2048-, and 4096-bit keys respectively. These levels may further drop because Heninger’s team did all the coding by hand and used no AI or GPUs in performing the forgeries. The researcher said these tools will “almost certainly” drop the security levels further.

    The attack works only against blind-signature implementations of RSA. The overwhelming majority of RSA in use today provides PKCS or PSS padding, a format that adds data to the plaintext before it’s encrypted. It prevents ciphertext from being deterministic and makes it less vulnerable to side channel and similar attacks. Still, some real-world systems continue to use blind-signature, also known as textbook, RSA. The best-known example, Heninger said, is Privacy Pass, a protocol that allows users to authenticate themselves without revealing their identity. Privacy Pass is used by both Apple and Cloudflare, among many others.

    An attack on Privacy Pass would require an attacker to compromise a server belonging to Cloudflare, Apple, or another organization and generate 243 signatures. Heninger said the requirement “sounds [like] a lot, but is on the same order of magnitude of the network traffic that Cloudflare has said publicly it handles in about a day.” Most Privacy Pass implementations rotate keys regularly, a measure that greatly reduces, but doesn’t automatically eliminate, the chances of attacker success.

    The technique implements a variant of the number field sieve algorithm that was invented in 2007. This “‘special’ number field sieve” is used against an “oracle,” a weakness in RSA and some other cryptosystems that gives yes-or-no answers to specific queries. By performing a massive number of operations, attackers can gather enough information to decipher the ciphertext. (Again, this technique poses no practical threat against RSA that uses PKCS or PSS padding, because they eliminate the oracle.) While factoring a 1024-bit key requires an estimated 280 operations and 500,000 to 1 million CPU core-years, using the sieve to forge a signature took just (as noted earlier) 265 operations and 1,380 core-years.

    The paper’s authors and other researchers stress that the new attack poses little real-world threat. It does, however, drastically lower the estimated security of textbook RSA, and it does so in a way no one knew of previously.

    Cryptographers have worked furiously in recent years to devise alternative cryptosystems that aren’t vulnerable to quantum computing attacks. The new attack will further increase the urgency of completely moving away from the cryptosystem. The paper authors provide an easier-to-digest explainer here.

    break Faster RSA weve
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleReview: Apple’s hyper-pricey M5 Ultra Mac Studio made me into a vibe coder
    Next Article When the Correct Answer Is Nothing, What Does Your Pipeline Return?
    • Website

    Related Posts

    Chatbots

    YouTube Music gets more conversational with new AI features

    Chatbots

    How to Build a Landbot AI Chatbot That Actually Books Meetings (Step by Step)

    Chatbots

    Gemini 4 is almost ready, says new Google DeepMind chief

    Add A Comment
    Leave A Reply Cancel Reply

    Top Posts

    Towards Spec-Driven Test Automation: Part 1

    0 Views

    YouTube Music gets more conversational with new AI features

    0 Views

    An OpenAI Agent Hacked Australia’s Health Service. Their Government Found Out Months Later

    0 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews
    AI Tutorials

    Quantization from the ground up

    AI Tools

    David Sacks is done as AI czar — here’s what he’s doing instead

    AI Reviews

    Judge sides with Anthropic to temporarily block the Pentagon’s ban

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Most Popular

    Towards Spec-Driven Test Automation: Part 1

    0 Views

    YouTube Music gets more conversational with new AI features

    0 Views

    An OpenAI Agent Hacked Australia’s Health Service. Their Government Found Out Months Later

    0 Views
    Our Picks

    Quantization from the ground up

    David Sacks is done as AI czar — here’s what he’s doing instead

    Judge sides with Anthropic to temporarily block the Pentagon’s ban

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Facebook X (Twitter) Instagram Pinterest
    • About Us
    • Contact Us
    • Terms & Conditions
    • Privacy Policy
    • Disclaimer

    © 2026 ainewstoday.co. All rights reserved. Designed by DD.

    Type above and press Enter to search. Press Esc to cancel.