hn.today

Forging 1024-bit RSA signatures in nearly SNFS time [pdf]

eprint.iacr.org64 points14 comments
Screenshot of Forging 1024-bit RSA signatures in nearly SNFS time [pdf]

Commenters focused on a new result that forges 1024-bit RSA signatures much faster by exploiting access to a "raw" RSA oracle. tptacek emphasized that the attack needs an API that performs RSA operations without padding, and that the paper discusses how such oracles can arise in practice (section 5). deprave echoed that "raw" means no padding and noted this is rarer than a generic signing oracle. nk_kolja highlighted that the theoretical foundation goes back to a 2007 Joux et al. result and praised the implementation achieving a practical 1024-bit forgery, while RossBencina wondered whether real-world code-signing tokens (e.g., shipped USB tokens) might be usable as oracles.

Opinion divides sharply on practical significance. pseudohadamard argued the paper is overhyped panic-mongering, saying standards already disallow textbook RSA so most real systems are not vulnerable and publicity could cause unnecessary alarm or erroneous CVEs. upofadown corrected terminology, noting blind signatures and textbook RSA are different, while yababa_y mocked the formal title in the PDF and angry_octet called out exaggerated framing. bflesch thanked others for clarifying the technical nuance, reflecting a segment of commenters seeking pragmatic clarification rather than alarm.

Read on eprint.iacr.org14 comments on Hacker News

Summary generated by AI from the linked article. hn.today is not affiliated with Hacker News or Y Combinator.

More in Security

The daily digest

Today's best Hacker News stories, summarized and screenshotted, one email a day.