Advertisement
Advertisement
Advertisement
26 September 2026ยท7 min readยทBy Marcus Thorne

New RSA Signature Forgery Attack Beats Factoring

New RSA attack research shows a signature forgery method reducing 1024-bit keys to 2^65 operations, far faster than factoring.

New RSA Signature Forgery Attack Beats Factoring

New RSA attack research has upended a belief that anchored cryptography for decades. Breaking RSA requires factoring enormous integers. That's the old rule. A team including Nadia Heninger, a professor at the University of California at San Diego, and led by Laura Shea, has demonstrated a signature forgery technique that sidesteps factoring entirely and slashes the computing resources needed to undermine RSA keys by orders of magnitude. Cryptographers are stunned. It's not because this threatens everyday encrypted traffic. But it dismantles a foundational assumption that no one had seriously challenged, and that's why they're reeling.

The Assumption That Just Cracked

For years, the security of RSA has rested on a simple premise. To forge a digital signature, an attacker would first need to derive the private key, which meant factoring a very large number. That task was considered prohibitively expensive. Cryptographers believed that computing valid RSA signatures without the private key was effectively impossible. For 1024-bit RSA, factoring was thought to cost tens of millions of dollars in computation time for a single key. For 2048-bit RSA, it was considered entirely out of reach.

Heninger and her coauthors, including lead author Laura Shea, showed that premise is wrong. Their method forges signatures directly, without ever factoring the key. The implications are immediate for older, deprecated key sizes and deeply concerning for the long-term security estimates of RSA at every size in use today.

How the Forgery Works

It's built on a variant of the number field sieve. That algorithm was invented in 2007, and it's known as the "special" number field sieve, which is the technical foundation the whole technique rests on. It exploits a property called an oracle. Some cryptographic protocols expose that oracle by answering queries about their inputs, and by performing a massive number of operations, an attacker can gather enough information to decipher ciphertext or forge a signature.

This is where the numbers get uncomfortable. Factoring a 1024-bit key is estimated to require roughly 2^80 operations and between 500,000 and 1 million CPU core-years. The forgery attack, by contrast, took just 2^65 operations and 1,380 core-years. Heninger's team ran the attack against 1024-bit keys on an academic CPU cluster over a handful of months. No GPUs. No AI. Just hand-coded software.

If this result holds up under peer review, it would be a conceptual breakthrough, Karsten Nohl, a cryptography expert and head of innovation at Allurity, said in an interview. RSA is hard to break. It's as difficult to break as it is to factor large integers, at least so we thought. And the researcher suggests that you can practically break RSA without cracking its key.

The security levels for larger keys drop sharply as well. The forgery attack reduces RSA security to 2^65 for 1024-bit keys, 2^90 for 2048-bit keys, and 2^119 for 4096-bit keys.

Market Context: According to IBM and the Ponemon Institute, the global average cost of a data breach reached an all-time high of USD 4.45 million in 2023.
The National Security Agency, the National Institute of Standards and Technology, and the European Union Agency for Network and Information Security all require cryptosystems to provide at least 128 bits of security, meaning operations must exceed 2^128. None of these key sizes meet that bar under the new attack.

Limited Real-World Risk, For Now

The attack only works against blind-signature implementations of RSA. That's textbook RSA. The overwhelming majority of RSA deployed today, however, uses PKCS or PSS padding, which adds data to the plaintext before encryption and prevents the ciphertext from being deterministic, so it's a different setup entirely. Those implementations remain safe from this particular technique. Why? They're providing a different type of oracle.

green LED numbers

Blind-signature RSA is not extinct. Some real-world systems still rely on it, and the best-known example is Privacy Pass, a protocol that lets users authenticate themselves without revealing their identity. Apple and Cloudflare are among the organizations that use it.

Launching an attack on Privacy Pass would require requesting 2^43 tokens from Cloudflare, Apple, or another provider. That sounds like a lot. Heninger acknowledged that. But it's on the same order of magnitude as the network traffic Cloudflare has said publicly it handles in about a day, which is a comparison that makes the number feel far less abstract than it first appears. Most Privacy Pass implementations rotate keys regularly. That greatly reduces the odds. It doesn't eliminate them.

The Road Ahead

Heninger's team did all their coding by hand. They used no AI or GPUs to perform the forgeries. She said those tools will "almost surely" push the security levels lower still, and that prospect is what has cryptographers paying attention, even as they stress that the immediate practical threat remains small. It's small.

The broader consequence is a further erosion of confidence in RSA itself. Researchers have spent years racing to build alternative cryptosystems that can withstand quantum computing, which is estimated to become practical within 3 to 20 or more years. The new RSA attack does not wait for quantum machines. It reduces the estimated security of the world's most widely deployed public-key cryptosystem using classical hardware that exists today.

  • The forgery attack works only against blind-signature RSA, not PKCS or PSS padding.
  • 1024-bit keys fell in months on an academic CPU cluster.
  • Security levels drop to 2^65, 2^90, and 2^119 for 1024-, 2048-, and 4096-bit keys.
  • Privacy Pass, used by Apple and Cloudflare, is the most prominent real-world target.

For anyone still running 1024-bit RSA, the message is blunt. For everyone else, the new RSA attack is a reminder that assumptions in cryptography have a shelf life, and this one just expired.

Frequently Asked Questions

What is the new RSA signature forgery attack and how does it differ from traditional RSA breaking methods?

The new RSA attack demonstrates a signature forgery technique that sidesteps factoring entirely and slashes the computing resources needed to undermine RSA keys by orders of magnitude. Traditionally, breaking RSA required factoring enormous integers, but this method forges signatures directly without ever factoring the key.

Who led the research team that discovered this new RSA attack, and what were the key findings?

The research team was led by Laura Shea and included Nadia Heninger, a professor at the University of California at San Diego. They demonstrated a signature forgery technique that forges signatures directly without factoring, reducing the security levels for RSA keys to 2^65 for 1024-bit keys, 2^90 for 2048-bit keys, and 2^119 for 4096-bit keys.

How does the forgery attack work technically, and what resources were used to execute it?

The forgery attack is built on a variant of the number field sieve known as the 'special' number field sieve, which exploits a property called an oracle exposed by some cryptographic protocols. Heninger's team ran the attack against 1024-bit keys on an academic CPU cluster over a handful of months, using no GPUs or AI, just hand-coded software, and it took 2^65 operations and 1,380 core-years.

Which RSA implementations are vulnerable to this attack, and which remain safe?

The attack only works against blind-signature implementations of RSA, also known as textbook RSA. The overwhelming majority of RSA deployed today uses PKCS or PSS padding, which adds data to the plaintext before encryption and prevents the ciphertext from being deterministic, so those implementations remain safe from this particular technique.

What are the practical implications of this new RSA attack for real-world systems like Privacy Pass?

Blind-signature RSA is not extinct, and the best-known real-world example is Privacy Pass, a protocol used by Apple and Cloudflare that lets users authenticate without revealing their identity. Launching an attack on Privacy Pass would require requesting 2^43 tokens, which is on the same order of magnitude as the network traffic Cloudflare handles in about a day, though most implementations rotate keys regularly, greatly reducing the odds.

Marcus Thorne
Written by
Senior AI Reporter

Marcus Thorne covers the fast-moving field of artificial intelligence, with a particular interest in large language models, automation and the companies driving the technology forward. He aims to cut through the hype and explain what these systems can and cannot do.

๐Ÿ’ฌ Comments (0)

Sign in to leave a comment.

No comments yet. Be the first!

Advertisement