New Classical Attack Lowers RSA Security but Poses Little Immediate Threat
New classical method cuts RSA security by orders of magnitude via signature forgery, but widely used keys remain safe.
RSA’s long-term vulnerability to quantum computing has been known for decades. Estimates for practical quantum computing range from three to 20 or more years. Once such machines become available, the foundational security RSA provides would crumble. The new work matters because it uses classical computing, not quantum computing, to lower the current RSA security level to what the report describes as an unacceptably low threshold. Ars Technica described the approach as a new way to break RSA that is faster than anything seen before.
The practical barriers remain severe. According to Ars Technica, even when the attack is applied against the deprecated use of 1024-bit keys, it requires more computation than almost anyone short of nation-states or companies with massive resources can achieve. Widely used RSA implementations are safe. The finding therefore does not threaten ordinary deployments at present.
The attack’s significance lies in its approach. It introduces signature forgery as a new way to break RSA keys without factoring. That departure from the usual focus on factoring is what took cryptographers by surprise. Equally important, the method reduces the required computing resources by orders of magnitude, according to the report.
The report frames the finding against a broader expectation that RSA is living on borrowed time. Quantum computing is expected to end the cryptosystem’s usefulness eventually, but the estimates for that range from three to 20 or more years. The new classical method does not change the immediate risk picture for widely used RSA. It does, however, show that classical techniques can push the security level down further than previously demonstrated, and it does so through a signature-forgery route rather than factoring.
For now, the research is most relevant to organizations and observers tracking cryptographic risk. Nation-states or companies with massive resources would still need extraordinary computing power to mount the attack, and the deprecated 1024-bit key scenario is already discouraged. The report identifies only a few edge cases as possible immediate concerns.
Editor's Summary
Researchers have described a classical-computing attack that reduces RSA security by orders of magnitude through signature forgery, surprising cryptographers. The method requires enormous resources and does not currently threaten widely used RSA implementations, though it may affect a few edge cases. It adds urgency to long-standing concerns about RSA's long-term viability.