The RSA cryptosystem, long considered a cornerstone of secure online transactions, faces a new and formidable challenge. Recent research has unveiled a novel classical computing technique that significantly reduces the security of RSA keys, making them more vulnerable than previously thought.
The new method, discovered by a team of researchers, allows for the creation of valid RSA digital signatures without the need to factor the key. For 1024-bit RSA, this breakthrough means that an academic CPU cluster could potentially break the security in just a few months. While widely used RSA implementations remain safe, the implications for deprecated 1024-bit keys are concerning.
“If this result holds up under peer review, it would indeed be a conceptual breakthrough,” says Karsten Nohl, a cryptography expert. “RSA is as difficult to break as it is to factor large integers, at least so we thought. The researcher suggests that you can practically break RSA without cracking its key.”
The attack, devised by Nadia Heninger and her colleagues, is particularly concerning because it reduces the required computing resources by orders of magnitude. For 1024-bit RSA, the attack is now fully practical, even if it is less feasible for 2048- and 4096-bit keys, which still offer a level of security that meets the requirements set by the National Security Agency and the National Institute of Standards and Technology.
The research highlights the need for a comprehensive shift towards stronger cryptographic methods, as the current RSA security levels are no longer considered sufficient. As quantum computing progresses, these new vulnerabilities could have far-reaching implications for digital security across the globe.







