New Forgery Attack on RSA Reduces Key Security Levels Significantly

Published:

CHAPTER X // CYBER AWARENESS CAMPAIGN
BEYOND THE BALLROOM
[C://ME] // CHAPTER X

REQUEST THE MEDIA KIT

Tell us where to send the Beyond the Ballroom media deck. Every field is required.

We will use these details to respond to your media-kit request. Privacy Policy

A new forgery attack on RSA encryption has been reported, significantly reducing the security levels of 1024-, 2048-, and 4096-bit keys to 265, 290, and 2119 respectively. This development, detailed by researchers led by Heninger, indicates that these levels may decrease further as the team performed all coding manually without the aid of AI or GPUs, suggesting that the use of such tools could enhance the attack’s effectiveness. The findings were published by Ars Technica.

Vulnerability in Blind-Signature Implementations

The attack specifically targets blind-signature implementations of RSA, which are less common than those using PKCS or PSS padding. The latter formats add data to plaintext before encryption, making the ciphertext non-deterministic and less susceptible to various attacks. However, some systems still utilize blind-signature RSA, with Privacy Pass being a notable example. This protocol allows users to authenticate without revealing their identity and is employed by major companies like Apple and Cloudflare.

Potential Impact on Privacy Pass

To successfully exploit Privacy Pass, an attacker would need to request tokens from the service provider 243 times. While this may seem substantial, Heninger noted that it is comparable to the network traffic Cloudflare handles in a single day. Most implementations of Privacy Pass rotate keys regularly, which mitigates but does not completely eliminate the risk of successful attacks.

Technical Details of the Attack

The forgery technique employs a variant of the number field sieve algorithm, originally developed in 2007. This specialized version utilizes an “oracle,” a feature of certain cryptographic protocols that provides answers to specific queries. The attack requires significantly fewer operations compared to traditional key factoring methods; for instance, while factoring a 1024-bit key typically demands around 280 operations, forging a signature with this new method only requires 265 operations and approximately 1,380 core-years of computational effort.

Follow Cyber Warriors Middle East for further global cybersecurity developments.

Cyber Warriors Conclave Chapter X — Beyond the Ballroom

Related articles

Recent articles

NASA advances digital taxi and safe runway technologies for commercial aviation

NASA has made significant advancements in commercial aviation technologies aimed at enhancing safety and efficiency at airports. Researchers at NASA’s Ames Research Center, in...

Malicious Content Discovered on ‘third-party.com’ Domain Used in Over 1,700 Repositories

The domain "third-party.com," typically used as a documentation placeholder, has been identified as serving a ClickFix lure targeting Windows users while presenting a benign...

New MacSync Version Targets Crypto Enthusiasts with Advanced Infection Techniques

The emergence of the MacSync malware family marks a significant evolution in the landscape of cyber threats targeting macOS users, particularly those involved in...

Astrana Health Reports Data Breach Following Social Engineering Attack on Employees

Astrana Health has reported a data breach involving the theft of private and confidential information from its servers, following a social engineering attack that...