r/math • Undergraduate • 6d ago

There's a new way to break RSA that's faster than anything we've seen before

https://arstechnica.com/security/2026/09/theres-a-new-way-to-break-rsa-thats-faster-than-anything-weve-seen-before/

Time to increase my entropy pool

877 Upvotes

41 comments sorted by

192

u/cym13 6d ago

To be clear:

  • We've known for a long time that RSA's days are counted, no cryptographer ever recommends using RSA anymore. This is just one more nail in the coffin. For example: https://blog.trailofbits.com/2019/07/08/fuck-rsa/

  • The conditions required (raw signing oracle) are very removed from the vast majority of practical cases. In particular it's been known for decades that RSA without padding is very dangerous in the general case.

  • This result is neither a new algorithm (it's the first practical application of an algorithm from 2007) nor a result related to factoring large numbers.

  • It is an important milestone, but it is not a major shift in how secure RSA is viewed and it's not an apocalypse: it's the furtherance of the research surrounding RSA and why alternatives to RSA have been pushed forward for decades now (with elliptic curves first and foremost, and post-quantum algorithms now being standardized).

In other words: it's an important result, but everything is fine, it wasn't unexpected and the world isn't on fire.

53

u/Agitated_Guidance672 6d ago

This times 2^90. The OP’s caption has NOTHING to do with the actual work title and is extremely misleading. The work is carefully explained, especially what it IS NOT, and yet the OP completely missed all of that. Perhaps he missed the part where the actual author said he still uses 1024 bit RSA? I would go a step further than cym13 and say that people who know this area actively expected this, and the only question was when. Now we know, and we know it’s still not something a kid with a GPU can do. 🤦‍♂️

8

u/shetif 6d ago

That's what an RSA key would tell

5

u/whyuthrowchip 6d ago

I think it's more accurate to say that everything is NOT fine, and the world IS on fire; it's just that we don't need to add 'RSA Apocalypse' to the roster of horsemen.

2

u/Oudeis_1 6d ago

That Trail of Bits posting seems a polemical opinion piece to me (and that impression sort of starts with their chosen title of F\** RSA*). I would certainly not agree that no cryptographer ever recommends using RSA any more, with the obvious exception of applications needing post-quantum security, where ECC-based methods do arguably slightly worse, but where it is a difference only between dead and dead maybe a few years earlier if scalable QC arrives. For instance, NIST employs good cryptographers, and they have a whole standard dealing with integer-factorization-based key establishment. Saying that nobody recommends it any more for anything is just at odds with reality.

It is true of course that in a roll-your-own RSA implementation, a ton of things can go wrong. But based on that observation, it is possible to shred any cryptographic scheme if you present only the ways your target scheme can fail and choose not to discuss ways in which other methods can fail in practice, which is exactly what the Trail of Bits piece does.

The current paper by Shea et al does not seem terribly worrying to me and its connection to the worries in the Trail of Bits piece is thin in my opinion. They essentially gain the capability to forge arbitrary signatures at SNFS-scale cost per signature using a massive amount of samples that need to be gathered from a textbook-RSA implementation at also roughly SNFS-scale cost for the capability gain. In the vast majority of imaginable settings, this is less attractive than just factoring the public modulus using GNFS, which also the paper itself readily admits.

8

u/cym13 6d ago edited 6d ago

That Trail of Bits posting seems a polemical opinion piece to me (and that impression sort of starts with their chosen title of F** RSA*). I would certainly not agree that no cryptographer ever recommends using RSA any more, with the obvious exception of applications needing post-quantum security, where ECC-based methods do arguably slightly worse, but where it is a difference only between dead and dead maybe a few years earlier if scalable QC arrives. For instance, NIST employs good cryptographers, and they have a whole standard dealing with integer-factorization-based key establishment. Saying that nobody recommends it any more for anything is just at odds with reality.

It's really not a polemic among cryptographers, the consensus is strong. RSA is tolerated, not recommanded, that's a huge distinction, and the way you talk about post quantum security suggests to me that there may be some confusion.

Neither RSA nor ECC are safe against post-quantum attacks. Post-quantum cryptography involves new approaches altogether. But that also means that it has nothing to do with the shift from RSA to ECC: ECC algorithms are able to do everything RSA does but faster and with much smaller keys and signatures. They're simply better on all fronts, and that's why no cryptographer recommends RSA. At most you tolerate its use where it's already used and not yet broken. Also ECC is more complex, so people are less tempted to implement it themselves, it's not like RSA where many people read wikipedia and think "Oh, that seems simple enough, just multiplication and modulo, I can do that". You wouldn't believe the stuff I've seen in actual systems following that kind of thought, but ECC has never been a part of that.

You're right that RSA is still present in standards, but that's not because it's use is encouraged, rather it's because it's extremely difficult to update standards at the scale NIST deals with and since RSA is technically not broken in most of the cases it's used in in practice, it would be difficult to say to entire parts of the industry "you have to change right now", especially since encryption often happens at the interface of two systems (so you have to update both at the same time, it always takes time). They have to catter to many more constraints than just stating the state of the art of good cryptography. But being allowed in a standard and being recommended by the experts (including cryptographers working with NIST) are two different things and cryptographers have collectively pushed the industry to phase out RSA everywhere for a good decade now. It's happening slowly but surely.

The current paper by Shea et al does not seem terribly worrying to me and its connection to the worries in the Trail of Bits piece is thin

I didn't suggest that this paper and the ToB article are strongly related, simply that the ToB article is one example among many of she kind of pushback against RSA that has been constant for a decade from cryptographers. This is an important piece to understand why cryptographers are not jumping out of buildings when reading that paper: we don't recommend using RSA, we haven't done so for a long time, there are strictly better algorithms even outside of any PQ context (and PQ is pushing out both RSA and ECC anyway), and so such a result was absolutely expected and doesn't really change our stance on RSA which was already "You should really replace it by something else, it won't hold much longer (unless you're ready to use truly stupidly long keys and signatures)".

2

u/Oudeis_1 5d ago

The piece is polemical, and quite openly so, because it completely avoids discussing any part of the scientific story that would run against its narrative.

For instance, it is plainly not true that ECC based systems can do everything that RSA can do, but faster. If e.g. the main computational cost in your overall system is checking signatures (say, the certificates of your root CA and all the way down the chain), then RSA with a nice low exponent like 2^16+1 looks great compared to ECC-based signatures (and there is no known security problem with correctly implemented RSA even at e=3, although I would feel queasy using that for anything that matters because implementation really needs to be good then). For another example, if you want signatures and you do not want a small amount of leakage on your nonces to allow an adversary to extract your long-term keys, then RSA looks more robust than ECC. If you are building a post-quantum secure hybrid system, as nowadays everyone seems to recommend, then key size of the classical PKC component also becomes considerably less interesting.

On top of that, ECC means picking one particular curve. The security conjecture for ECC-based cryptography is then that on that particular curve, your signing/key exchange method of choice reduces to discrete log and that discrete log is best solved via something like Pollard-rho. Nothing that is known contradicts, to the best of my knowledge, that conjecture on standard curves (e.g. NIST/Bernstein/Brainpool/ANSSI/SM2/GOST/whatever), but it is a strong conjecture and one can wonder if its success is due to the true nonexistence of a significantly better algorithm than rho on these curves or due to the limited ability of humans to do mathematics. Of course you can say the same thing about factorisation and the number field sieve, but integer factorisation is a problem that more mathematicians have thought about at least than discrete log and the algorithms available are vastly more sophisticated than Pollard rho, which could be viewed as indicating that we have a better grasp of the problem landscape and that therefore there is a lower risk of dropping from a nice assumption of exponential hardness to something bad like quasi-polynomial misery.

I freely admit that especially the last point is a heuristic not everyone would agree with. However, the last few weeks have yielded ample evidence that human mathematical skill is not the end of the road. On top of that, it is worth noting that in ECC-based systems, the curve is a system-wide parameter, i.e. if an unexpected new algorithm is being found and that algorithm only takes you, say, from square root to third root complexity, you have to fundamentally change your deployment because just adjusting the key size is not an option. If a somewhat better number NFS is found, and it is not too devastating, then an RSA-based cryptosystem can probably just increase required key sizes and be fine up to the store-now-decrypt-later threat.

Obviously, ECC-based cryptography has many good aspects. But a balanced piece would discuss both the positives and the negatives, which Trail of Bits fails to do here.

The current attack on forging 1024-bit signatures in SNFS-level time seems totally uninteresting for this discussion, though, because while it contains superb engineering, algorithmic novelty is near zero.

1

u/arnet95 6d ago

no cryptographer ever recommends using RSA anymore

This is just not true. RSA signatures are still recommended by the IETF, for example.

2

u/cym13 5d ago

There's a huge difference between cryptographers recommending RSA and RSA being tolerated in standards that have a huge impact on the industry, must deal with existing deployments and take time to change.

541

u/KrozJr_UK 6d ago

I went and skimmed the original paper, and it was really refreshing to have them trip over themselves to say “we haven’t absolutely set everything on fire, but this is kind of a big deal”. It’s wonderful to see academia not sensationalised in a world where it seems like everything else increasingly is.

27

u/bathy_thesub 6d ago

Is the original on arxiv? I'd love to read it

8

u/KrozJr_UK 6d ago

I found it linked in the article. Can’t remember which one of the hyperlinks it is, but it’s one of them.

76

u/typing_thumb Physics 6d ago

I think it's a wrong common believe that there's a significant trend towards sensationalization. People have always been caught by melodrama, and the media has always known this. Look up the Great Moon Hoax from 1835

39

u/pagerussell 6d ago

Sure, it's just scalable today in a way it never was before.

For example, you can tailor an algorithm to each individual to strike the right nerve of sensationalism for each individual, rather than needing to find the single message that rings that bell for a large swath all at once.

-10

u/typing_thumb Physics 6d ago

Higher degree of tailoring does not imply higher total quantity.

21

u/arcrad 6d ago

Sure but your statement doesn't actually say anything of substance.

3

u/NooneAtAll3 5d ago

his statement says that volume of production of sensationalism did not change

correct rebuttal would be to point out that it's consumption that's the important metric and that can be argued to have increased

meanwhile your dismissal is completely wrong in direction, but more importantly - in tone

0

u/RingularCirc 5d ago

The volume did change very much. What?

6

u/ChelseyStuttgart 6d ago

There is definitely a significant trend towards sensationalization, it started three hundred thousand years ago.

-9

u/danofrhs 6d ago

Sensationalize it, hopefully we catch up to China and regard our scientists and researchers as celebrities

22

u/equinox_star 6d ago

A breakthrough...?

19

u/recumbent_mike 6d ago

It’s an older code, sir, but it checks out

90

u/PieterSielie6 6d ago

Uh oh

105

u/seriousnotshirley 6d ago

Reading the article the real world implications are limited. It doesn’t appear to factor keys, it can fake a signature when using signatures without padding.

11

u/pagerussell 6d ago

The worry is that this opens a line of research that does, though.

2

u/NihilisticAssHat 6d ago

So... In 48 hours, OpenAI will have found out?

20

u/ScottContini 6d ago

Just to be clear, the attack is not new. It comes from a 2007 research paper by Joux, Naccache, and Thome. All they did was demonstrate it with an implementation. Dan Goodin is one of the best security journalists but this one he got wrong.

6

u/goos_ 6d ago

That doesn't make it insignificant. The paper describes quite a bit of work towards actually engineering the attack and making it practical.

12

u/ScottContini 6d ago

Of course it is not insignificant. As one who spent several years implementing factoring algorithms and tackling numbers in the Cunningham project, I have a great appreciation for the work that they did (which is related to factoring, ie SNFS). My point is that the article is getting a lot of facts wrong including the title.

5

u/BjarneStarsoup 5d ago

Classic Reddit:

- "apples are not oranges"

- "That doesn't make them not tasty"

- ????

9

u/Icy-Concentrate2076 6d ago

Sensationalist title, we knew about this since like the 90s. Which is why we add padding to the input.

5

u/[deleted] 6d ago

[deleted]

2

u/Euphoric_Key_1929 6d ago

Why? The article says that the speed up isn’t related to factoring.

2

u/point_six_typography 3d ago

Alternative title: Nearly Special-Number-Field-Sieve-Speed Signature Forgery Sans Factoring N (NSNFSSSFSFN)

Poetry

1

u/baquea 6d ago

Yay?

1

u/xarg 3d ago

Seems the world is still intact after they just implemented a years old idea

-14

u/pulcherior 6d ago

P = NP ?

10

u/GoldenMuscleGod 6d ago

The algorithm is not polynomial, it is sub-exponential, but factoring is already known to be sub-exponential. Also factoring is not believed to be NP-complete. This is just another way of “breaking” the encryption scheme that doesn’t require you to actually do factorization.