- Sources: paper, discussion
- Summary: The preprint, posted to the Cryptology ePrint Archive on 2026-09-22 and not peer reviewed, implements a 2007 algorithm against 1024-bit RSA with 1380 CPU core-years in total, most of it precomputation, and 2^32 oracle queries, after which any chosen signature is forged offline in 180 core-years and the private key is never factored. The authors ran the attack against a hardware security module and impersonated it through black-box API calls with no key exfiltration. They place RSA signing-oracle security 15 to 30 bits below factoring-based estimates across 1024-bit to 4096-bit keys, and state that even 4096-bit RSA does not reach 128-bit security in this model.
- Why it matters: The exposed surface is signing oracles such as HSM APIs and blind RSA schemes rather than ordinary certificate verification, and the stated margin puts 4096-bit RSA below 128-bit security there.
- Follow-up: Track peer review of the preprint and any HSM vendor response on query limits for RSA signing APIs.
send feedback on this story