EDITION OF FRI 25 SEP 2026
202 · TECHNOLOGY

Researchers demonstrate RSA signature forgery without factoring keys

publishers 6articles 6first reported 24 Sep, 11:15 UTCdeveloping since 24 Sep · 3 editions

Researchers have demonstrated a classical-computing technique that can forge RSA digital signatures without first factoring the public key’s modulus, challenging the long-held assumption that defeating RSA requires solving the underlying factoring problem.

According to Ars Technica, the researchers completed an attack against a deprecated 1,024-bit RSA key in several months using an academic CPU cluster. Estimates for factoring a key of that size have typically involved computing resources available only to large technology companies or national intelligence agencies, potentially costing tens of millions of dollars for a single key.

Nadia Heninger, a University of California, San Diego professor and co-author of the research, said the forgery method is practical for 1,024-bit RSA. The researchers also found that it lowers the security offered by 2,048- and 4,096-bit keys.

The immediate risk is limited: 1,024-bit RSA has been deprecated, and widely used RSA implementations are reported to be safe from the demonstrated attack. However, the method reduces the computing resources needed to attack affected RSA signatures by orders of magnitude.

Cryptography expert Karsten Nohl said the result would represent a conceptual breakthrough if it withstands peer review, because it provides a route to producing valid signatures without recovering the private key.

HOW THIS STORY WAS MADE

Written from 6 articles, 1 with the publisher's own text; 6 independent newsrooms once syndicated copies count as one; this version written 20 h after the record first saw the story; the editor revised it.

Publishers
6
Source articles
6
Given to the writer
6, 1 with the article's own text
Independent newsrooms
6
This version written
20 h after the record first saw the story
Second model (editor)
revised
Publication gate
passed
Human review
none

Written by a language model from the sources above, then checked by a second model that may only cut, attribute or correct. How it works →

NAMED IN THE COVERAGE

OUTLETS CARRYING THE STORY, RUN BY RUN

0 3 6 25 Sep 26 Sep 25 Sep 06:24 UTC · Researchers demonstrate RSA signature forgery without factoring keys 25 Sep 12:26 UTC · Researchers demonstrate RSA signature forgery without factoring keys

WHAT HELD, WHAT CAME LATER

From the first reports to the latest

  • Nothing ran from the first third of the coverage to the last.

Entered the story later

  • Nothing new took hold after the first third.

HOW THIS STORY DEVELOPED: EVERY HEADLINE, EVERY OUTLET →