As cited
Copy frozen at (site build).
research
New Attack Against RSA
Researchers have demonstrated a practical attack that forges RSA digital signatures without recovering the private key, based on algorithmic work from 2007 but with new implementation techniques. The attack works only on unpadded signatures and remains subexponential in complexity, requiring roughly 1,380 CPU core-years to forge a 1,024-bit RSA signature. This does not represent a fundamental break of RSA as commonly deployed in modern systems, which rely on padded signature schemes and larger key sizes.
Why it matters: Organizations relying on legacy unpadded RSA signatures or 1,024-bit keys should assess whether they are still in use; practitioners should verify their implementations use standard padding schemes and modern key lengths to remain unaffected by this attack.
- Source published
- First seen by Cybersecurity Tracker