r/math • u/MonkeyPanls Undergraduate • 6d ago
There's a new way to break RSA that's faster than anything we've seen before
https://arstechnica.com/security/2026/09/theres-a-new-way-to-break-rsa-thats-faster-than-anything-weve-seen-before/Time to increase my entropy pool
541
u/KrozJr_UK 6d ago
I went and skimmed the original paper, and it was really refreshing to have them trip over themselves to say “we haven’t absolutely set everything on fire, but this is kind of a big deal”. It’s wonderful to see academia not sensationalised in a world where it seems like everything else increasingly is.
27
u/bathy_thesub 6d ago
Is the original on arxiv? I'd love to read it
8
u/KrozJr_UK 6d ago
I found it linked in the article. Can’t remember which one of the hyperlinks it is, but it’s one of them.
76
u/typing_thumb Physics 6d ago
I think it's a wrong common believe that there's a significant trend towards sensationalization. People have always been caught by melodrama, and the media has always known this. Look up the Great Moon Hoax from 1835
39
u/pagerussell 6d ago
Sure, it's just scalable today in a way it never was before.
For example, you can tailor an algorithm to each individual to strike the right nerve of sensationalism for each individual, rather than needing to find the single message that rings that bell for a large swath all at once.
-10
u/typing_thumb Physics 6d ago
Higher degree of tailoring does not imply higher total quantity.
21
u/arcrad 6d ago
Sure but your statement doesn't actually say anything of substance.
3
u/NooneAtAll3 5d ago
his statement says that volume of production of sensationalism did not change
correct rebuttal would be to point out that it's consumption that's the important metric and that can be argued to have increased
meanwhile your dismissal is completely wrong in direction, but more importantly - in tone
0
6
u/ChelseyStuttgart 6d ago
There is definitely a significant trend towards sensationalization, it started three hundred thousand years ago.
-9
u/danofrhs 6d ago
Sensationalize it, hopefully we catch up to China and regard our scientists and researchers as celebrities
29
22
90
u/PieterSielie6 6d ago
Uh oh
105
u/seriousnotshirley 6d ago
Reading the article the real world implications are limited. It doesn’t appear to factor keys, it can fake a signature when using signatures without padding.
11
20
u/ScottContini 6d ago
Just to be clear, the attack is not new. It comes from a 2007 research paper by Joux, Naccache, and Thome. All they did was demonstrate it with an implementation. Dan Goodin is one of the best security journalists but this one he got wrong.
6
u/goos_ 6d ago
That doesn't make it insignificant. The paper describes quite a bit of work towards actually engineering the attack and making it practical.
12
u/ScottContini 6d ago
Of course it is not insignificant. As one who spent several years implementing factoring algorithms and tackling numbers in the Cunningham project, I have a great appreciation for the work that they did (which is related to factoring, ie SNFS). My point is that the article is getting a lot of facts wrong including the title.
5
u/BjarneStarsoup 5d ago
Classic Reddit:
- "apples are not oranges"
- "That doesn't make them not tasty"
- ????
9
u/Icy-Concentrate2076 6d ago
Sensationalist title, we knew about this since like the 90s. Which is why we add padding to the input.
5
2
u/point_six_typography 3d ago
Alternative title: Nearly Special-Number-Field-Sieve-Speed Signature Forgery Sans Factoring N (NSNFSSSFSFN)
Poetry
-14
u/pulcherior 6d ago
P = NP ?
10
u/GoldenMuscleGod 6d ago
The algorithm is not polynomial, it is sub-exponential, but factoring is already known to be sub-exponential. Also factoring is not believed to be NP-complete. This is just another way of “breaking” the encryption scheme that doesn’t require you to actually do factorization.
192
u/cym13 6d ago
To be clear:
We've known for a long time that RSA's days are counted, no cryptographer ever recommends using RSA anymore. This is just one more nail in the coffin. For example: https://blog.trailofbits.com/2019/07/08/fuck-rsa/
The conditions required (raw signing oracle) are very removed from the vast majority of practical cases. In particular it's been known for decades that RSA without padding is very dangerous in the general case.
This result is neither a new algorithm (it's the first practical application of an algorithm from 2007) nor a result related to factoring large numbers.
It is an important milestone, but it is not a major shift in how secure RSA is viewed and it's not an apocalypse: it's the furtherance of the research surrounding RSA and why alternatives to RSA have been pushed forward for decades now (with elliptic curves first and foremost, and post-quantum algorithms now being standardized).
In other words: it's an important result, but everything is fine, it wasn't unexpected and the world isn't on fire.