{"id":904522,"date":"2026-09-25T03:54:14","date_gmt":"2026-09-25T03:54:14","guid":{"rendered":"https:\/\/www.newsbeep.com\/au\/904522\/"},"modified":"2026-09-25T03:54:14","modified_gmt":"2026-09-25T03:54:14","slug":"new-technique-bypasses-1024-bit-rsa-without-factoring-it","status":"publish","type":"post","link":"https:\/\/www.newsbeep.com\/au\/904522\/","title":{"rendered":"New Technique Bypasses 1,024-Bit RSA Without Factoring It"},"content":{"rendered":"<p>The RSA encryption algorithm may be even more endangered now, courtesy of University of California, San Diego and Inria Nancy researchers.<\/p>\n<p>Cyber Security News <a href=\"https:\/\/cybersecuritynews.com\/new-way-to-break-rsa\/\" rel=\"false nofollow noopener\" target=\"_blank\">reported<\/a> that a new signature forgery attack detailed in the <a href=\"https:\/\/eprint.iacr.org\/2026\/2131.pdf\" rel=\"nofollow noopener\" target=\"_blank\">researchers\u2019 paper<\/a> deployed a novel method to crack 1,024-bit RSA encryption without factoring (finding the two primes used to create a key). The researchers were able to break encryption with an academic CPU cluster that dedicated 1,380 CPU core-years to the problem over five months. Factoring a 1,024-bit RSA key, Cyber Security News noted, has previously been estimated to require 500,000 to 1 million CPU core-years.<\/p>\n<p>RSA is not quantum-resistant, potentially meaning anything encrypted using it today could be broken by future attackers with access to a quantum computer. (The most obvious candidate is a nation-state.)<\/p>\n<p><a href=\"https:\/\/arstechnica.com\/security\/2026\/09\/theres-a-new-way-to-break-rsa-thats-faster-than-anything-weve-seen-before\/\" rel=\"nofollow noopener\" target=\"_blank\">Ars Technica<\/a> reported that the results bring even 2,048-bit and 4,096-bit keys to unacceptably low levels of security per standards published by the National Security Agency, the National Institute of Standards and Technology (NIST), and the European Union\u2019s main cybersecurity agency. The NIST already plans to deprecate RSA by 2030 and eliminate it by the middle of the next decade.<\/p>\n<p>\u201cIf this result holds up under peer review, it would indeed be a conceptual break-through,\u201d Allurity head of innovation and cryptographer Karsten Nohl told Ars Technica. \u201cRSA is as difficult to break as it is to factor large integers, at least so we thought.\u201d<\/p>\n<p>The technique relies on a variant of the number field sieve algorithm which Cyber Security News noted was first proposed in 2007, but which researchers hadn\u2019t run at this scale until now.<\/p>\n<p>This isn\u2019t a short-term threat. Beyond the immense computing capacity required, the technique doesn\u2019t appear to be effective against RSA using PKCS#1 v1.5 or PSS padding. Those techniques package extra data into encrypted communications to make them harder to crack, and are in widespread (but not universal) deployment today.<\/p>\n<p>UC San Diego professor and co-author Nadia Heninger told Ars Technica an attack on Apple\u2019s or Cloudflare\u2019s 2,048-bit implementation of Privacy Pass, which does not use either form of padding, would take about as many token requests as Cloudflare handles HTTP requests daily.<\/p>\n<p>Quantum computers capable of breaking RSA at scale are under development, but remain largely theoretical. Two studies earlier this year, however, <a href=\"https:\/\/arstechnica.com\/security\/2026\/03\/new-quantum-computing-advances-heighten-threat-to-elliptic-curve-cryptosystems\/\" rel=\"nofollow noopener\" target=\"_blank\">suggested<\/a> that breaking a separate public-key method called elliptic-curve cryptography may take fewer resources than previous estimates.<\/p>\n","protected":false},"excerpt":{"rendered":"The RSA encryption algorithm may be even more endangered now, courtesy of University of California, San Diego and&hellip;\n","protected":false},"author":2,"featured_media":904523,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[6],"tags":[64,63,284,31125,38823,23493,2457,2292,120438,105],"class_list":["post-904522","post","type-post","status-publish","format-standard","has-post-thumbnail","category-technology","tag-au","tag-australia","tag-cybersecurity","tag-encryption","tag-hackers","tag-passwords","tag-privacy","tag-quantum-computing","tag-rsa","tag-technology"],"_links":{"self":[{"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/posts\/904522","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/comments?post=904522"}],"version-history":[{"count":0,"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/posts\/904522\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/media\/904523"}],"wp:attachment":[{"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/media?parent=904522"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/categories?post=904522"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/tags?post=904522"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}