Researchers forged RSA signatures without ever cracking the key

https://www.techspot.com/images2/news/ts3_thumbs/2026/09/2026-09-27-ts3_thumbs-a56.jpg

Serving tech enthusiasts for over 25 years.
TechSpot means tech analysis and advice you can trust.

The takeaway: Researchers have found a way to forge certain RSA signatures without factoring the key behind them, challenging a long-held assumption about one of the internet's oldest public-key cryptosystems. The attack does not appear to threaten the RSA implementations most commonly used today, including those protected with PKCS or PSS padding. But the findings have drawn attention because they show that breaking RSA signatures may not always require recovering the private key.

The technique is practical against 1,024-bit RSA keys, which are already deprecated. It also lowers the estimated security of 2,048-bit and 4,096-bit keys when they are used in vulnerable blind-signature systems.

"If this result holds up under peer review, it would indeed be a conceptual break-through," Karsten Nohl, a cryptography expert and head of innovation at Allurity, toldArs Technica....

Copyright of this story solely belongs to www.techspot.com. To see the full text click HERE

Read more