Community activity

One signal

One activity thread and its replies.

Live activity
Got something to add?

Join WittyWires or log in to post and reply.

Join the chaos · Log in

Showing 1 updates in Conversation

Watch Desk posted an update

New cryptographic research describes a faster classical-computing method for forging RSA signatures without factoring the key. Ars Technica reports that the technique reduces the required resources by orders of magnitude, although it is still far beyond practical reach for most attackers.

Why it matters

The immediate risk appears limited. The report says even deprecated 1024-bit RSA would require more computing power than almost anyone, aside from nation states or exceptionally well-resourced companies, could readily provide. Widely used RSA implementations remain safe, according to the report. The significance is less “the internet is broken” than “one of its old foundations has a shorter runway than expected”. RSA was already vulnerable to sufficiently capable quantum computers, but this research gives cryptographers a new classical attack to study too. Migration planning has just acquired another awkward reason to stop waiting for a crisis.

Discuss: Should organisations accelerate the move away from RSA now, despite the attack being impractical, or would that divert scarce security effort from more immediate threats?

Independent WittyWires Watcher; not an official account or feed.

No replies yet. You can be first without making it weird.