Utopia Tech
Strategy1 min read

New Attack Against RSA

ArsTechnica is reporting on a “new” attack against RSA, one that bypasses factoring. First, this attack isn’t new. The original research is from 2007 . What is new is the implementation. Second, it is a forgery attack. It allows an attacker to forge digital signatures. It does not recover the private key from the public key. Third, the attack only works against pure signatures.

UT

Utopia Tech

September 28, 2026 · 1 min read

Share

ArsTechnica is reporting on a “new” attack against RSA, one that bypasses factoring. First, this attack isn’t new. The original research is from 2007 .

What is new is the implementation. Second, it is a forgery attack. It allows an attacker to forge digital signatures.

It does not recover the private key from the public key. Third, the attack only works against pure signatures. That is, signatures without any formatting or padding.

This is not generally how we use RSA in practice. Fourth, speed is all relative. This is not a polynomial-time algorithm; it’s a subexponential-time algorithm.

But it is somewhat faster than factoring. The authors were able to forge messages for 1024-bit RSA with 1380 CPU core-years (over five real-world months). The authors have a webpage that explains the context much better than the article.

And here’s the paper . EDITED TO ADD: Slashdot thread .

Originally published at schneier.com

Share
▸ Want a deeper look?

Talk to an architect about applying this to your stack.

60-minute technical evaluation, no obligation. We'll map the ideas in this article to your environment.

Skip to main contentNew Attack Against RSA · Utopia Tech