Elektrine lite

← Feed

@darkuncle@infosec.exchange

2026-09-28 22:04 UTC

Excellent research (and very useful FAQ) out on a new RSA attack: forging 1024-bit signatures in “nearly SNFS time” (not polynomial, but somewhat faster than previous number field sieve approaches by a few orders of magnitude). Real-world risk is low because most RSA implementations in practice do not meet one of the attack requirements; however … more ammunition on the need to transition away from RSA (and protocols like TLS moved to elliptic curve quite a while ago, or are moving to ML-KEM and #PQC). https://github.com/ucsd-hacc/NSNFSSSFSFN #cryptography tip o’ the hat to Bruce Schneier’s blog for raising it to my attention

Replies (1)

  • @phlogiston@mastodon.nz 2026-09-29 02:41

    @darkuncle@infosec.exchange An interesting thing is this: While TLS does not expose a weak mode of using RSA, the majority of X.509 certs on the web are RSA (approx. 2/3). See below for a link to the source for this. But certificates are also used for other things, e.g. code signing, token issuing, etc. And who knows whether any of those use cases will *always* be avoiding the classic RSA padding for signatures. So a move to the more efficient and compact ECDSA or (even (better)) to EdDSA would be appreciated. This move will also more likely level the path towards allowing for better cryptographic agility to adopt hybrid #PQC ciphers in the future. BTW, kudos to Let's Encrypt! There the entire chain is using ECDSA signed certs down to the web site using it. https://ecdsa.com/research #cryptography #RSA #ECC

    Open ##4889735