There’s a new way to break RSA that’s faster than anything we’ve seen before

by | Sep 28, 2026 | Technology

There's a new way to break RSA that's faster than anything we've seen before

A novel attack against RSA encryption has been unveiled by cryptography researchers, introducing what experts describe as a conceptual breakthrough in breaking the widely-used cryptosystem. Unlike previous understanding that factoring was the only practical approach to compromise RSA keys, the new method employs a variant of the number field sieve algorithm to forge digital signatures without requiring the private key.

The attack specifically targets blind-signature implementations of RSA, known as textbook RSA, which lack the protective padding formats used in most modern deployments. For 1024-bit RSA keys, researchers successfully completed the attack using a handful of months of computation on an academic CPU cluster, a dramatic reduction compared to current factoring estimates that would require resources available only to large organizations or nation-states. The method reduces security levels from the required minimum of 128 bits to 65 bits for 1024-bit keys, 90 bits for 2048-bit keys, and 119 bits for 4096-bit keys.

While the overwhelming majority of RSA implementations in use today employ PKCS or PSS padding, which provides protection against this attack, certain real-world systems continue to rely on unpadded RSA. Privacy Pass, a protocol allowing authentication without identity disclosure and used by organizations including Apple and Cloudflare, represents a known vulnerable application. An attack against Privacy Pass would require approximately 2^43 token requests, a quantity comparable to daily network traffic levels reported by major infrastructure providers.

Cryptography experts emphasize that practical risks remain limited at present, particularly given that many Privacy Pass implementations rotate keys regularly. However, the discovery that RSA can be compromised through signature forgery rather than factorization has surprised the cryptographic community and accelerated discussions about migration to quantum-resistant alternatives. Researchers note that improved implementation and the incorporation of advanced computational tools could potentially reduce security levels further.

Article Attribution | Read More at Article Source

Article summary produced by Claude AI