Majorother

There's a new way to break RSA that's faster than anything we've seen before

Published
Sep 24, 2026 11:15 UTC

Recent research led by Nadia Heninger, a professor at the University of California at San Diego, and reported by Karsten Nohl, head of innovation at Allurity, presents a novel approach to breaking RSA encryption that could significantly reduce the time and resources required for such attacks. This work suggests that RSA, traditionally considered secure due to the difficulty of factoring large integers, may be more vulnerable than previously thought.

The study indicates that factoring a 1024-bit RSA key could take a handful of months on an academic CPU cluster, with an estimated computational cost in the tens of millions of dollars. Specifically, the research estimates that approximately 2^80 operations are required to factor a 1024-bit key, translating to a demand of between 500,000 to 1 million CPU core-years. This finding raises concerns about the viability of 1024-bit RSA keys in the face of evolving computational capabilities.

Moreover, the research highlights the operations needed for signature forgery on a 1024-bit RSA key, which is estimated at 2^65 operations, requiring about 1,380 core-years. The implications of these findings extend to the security levels of RSA keys: after a forgery attack, the effective security levels drop to 2^65 for 1024-bit keys, 2^90 for 2048-bit keys, and 2^119 for 4096-bit keys. This suggests that even higher bit-length keys may not be immune to future attacks, particularly as computational power continues to grow.

A notable aspect of the research is its application to the Privacy Pass protocol, which allows user authentication without revealing identity. The study estimates that an attacker would need to generate 2^43 signatures to compromise this protocol, a number that aligns with the daily network traffic handled by Cloudflare, indicating a potential real-world risk.

Heninger asserts that this method allows for the practical breaking of RSA without needing to crack its key, marking a significant conceptual breakthrough in cryptography. If validated through peer review, these findings could prompt a reevaluation of current cryptographic standards and practices, particularly as the timeline for practical quantum computing approaches, estimated to be within 3 to 20 years. The implications of this research are profound, as they challenge the foundational assumptions about the security of RSA encryption in the digital landscape.

Summarised from the primary source with AI assistance under human editorial oversight. Turing Wire is not a primary source — read the original for the authoritative account.

Source: Ars Technica AI