Skip to content
Ars Technica·

🔒New Method Cracks RSA Security, Drops 4096-bit Keys to 2119-bit

RSA's days are numbered, but not for everyone

TL;DR

New research slashes RSA security levels, making 4096-bit keys vulnerable. But standard implementations remain safe, and the attack is limited to specific use cases.

A new method has emerged that significantly weakens RSA security, reducing 4096-bit keys to a mere 2119-bit level. This breakthrough could shake the foundations of cryptographic security, but the impact is limited to specific implementations. Most widely used RSA systems, like PKCS and PSS padding, are unaffected. The real threat lies in blind-signature RSA, used in niche applications like Privacy Pass. If you're using blind-signature RSA, start planning your migration now. The attack, however, requires significant computational resources, making it impractical for most attackers. But the long-term implications are clear: RSA's days as a go-to encryption method are numbered.

New Method Cracks RSA Security, Drops 4096-bit Keys to 2119-bit — Ars Technica

Key Points

1

New method reduces 4096-bit RSA keys to 2119-bit security level, posing a significant threat to cryptographic security.

2

Most RSA implementations using PKCS or PSS padding are unaffected by the new attack method.

3

The attack works against blind-signature RSA, used in niche applications like Privacy Pass, which rotates keys regularly.

4

Generating 243 signatures to exploit a Privacy Pass system would require compromising a Cloudflare, Apple, or similar server.

5

The number field sieve algorithm variant used in the attack was invented in 2007, now applied to RSA security.

Why It Matters

If you're using blind-signature RSA in niche applications like Privacy Pass, the new attack method drops your security levels significantly. For 4096-bit keys, the security drops to 2119-bit, making them vulnerable. However, standard RSA implementations with PKCS or PSS padding remain safe. The attack requires significant computational resources, limiting its immediate threat, but long-term implications are clear: RSA's days are numbered.

rsaquantum-computingcryptographic-attackblind-signatureprivacy-pass

Comments

Subscribe to join the conversation...

Be the first to comment

Enjoyed this article?

Get it daily. 7am. Free. Reads in 5 minutes.

Join 3,496 builders reading daily.

Also get