ePrint 2026/2131 + Ars (24 Sep): forge 1024-bit RSA signatures in nearly SNFS time without factoring the key
Cryptology ePrint Archive paper 2026/2131 (“Forging 1024-bit RSA signatures in nearly SNFS time”; Laura Shea, Miro Haller, Adam Suhl, Nadia Heninger, Emmanuel Thomé) and Ars Technica (Dan Goodin, 24 September 2026) describe a classical-computing signature-forgery method that breaks RSA without factoring the modulus — building on an under-appreciated 2007 Joux–Naccache–Thomé oracle algorithm. Practical demonstration: forging against deprecated 1024-bit RSA took a handful of months on an academic CPU cluster, far below nation-scale GNFS factoring estimates for that size. Authors and independent cryptographers (quoted in Ars) stress widely deployed RSA-2048+ implementations remain practically safe for now, but the result is a conceptual break from the long-held “RSA security ≈ factoring hardness” assumption and further argues against any remaining 1024-bit RSA. Peer review pending. Primary: ePrint 2026/2131; wire: Ars Technica 24 Sep.
- Product
- RSA signature schemes (research focus: 1024-bit / deprecated sizes)
- Versions
- n/a (cryptanalytic research; 1024-bit demonstrably forgeable under paper’s model; RSA-2048+ not practically broken per Ars/authors)
- Exploited in Australia?
- unknown
- Patch to
- Eliminate remaining 1024-bit RSA keys/certs; prefer RSA-2048+ or modern curves; treat any 1024-bit RSA still in PKI, code-signing, or legacy VPN/IKE as urgently retireable; watch peer-review follow-ups before changing 2048-bit guidance.
Primary: IACR ePrint 2026/2131 — Forging 1024-bit RSA signatures in nearly SNFS time · Vendor: ePrint PDF — 2026/2131 · Ars Technica — New way to break RSA without factoring (24 Sep 2026)
