Forget the Pixel 10a - this is the best Android phone under $500, and it just scored a rare discount at AmazonUse open weight models as your AI coding agent with Amazon BedrockSave $160 on this tiny Ryzen 7 Beelink SER8 mini PC with 32GB of DDR5 RAMGoogle’s new Googlebook OS is basically Android for laptopsSonos Beam Ultra review: one of the best compact Dolby Atmos soundbars aroundToday’s best laptop deals: Save big on work, school, home use, and gamingForget the Pixel 10a - this is the best Android phone under $500, and it just scored a rare discount at AmazonUse open weight models as your AI coding agent with Amazon BedrockSave $160 on this tiny Ryzen 7 Beelink SER8 mini PC with 32GB of DDR5 RAMGoogle’s new Googlebook OS is basically Android for laptopsSonos Beam Ultra review: one of the best compact Dolby Atmos soundbars aroundToday’s best laptop deals: Save big on work, school, home use, and gaming
Pull down to refresh stories
Courses Write Login VIVietnamese Store

There's a new way to break RSA that's faster than anything we've seen before

Once quantum computing becomes practical (estimates for that range from 3 to 20 or more years), the foundational security it provides will crumble.

The world has known for decades that the RSA cryptosystem ’s days are numbered. Once quantum computing becomes practical (estimates for that range from 3 to 20 or more years), the foundational security it provides will crumble. The useful part sits in the context, the practical impact, and what readers can use to decide the next step.

There's a new way to break RSA that's faster than anything we've seen before

The world has known for decades that the RSA cryptosystem ’s days are numbered. Once quantum computing becomes practical (estimates for that range from 3 to 20 or more years), the foundational security it provides will crumble.

What happened

New research has revealed a novel method that uses classical computing to reduce the current RSA security level to an unacceptably low threshold. This is still a developing thread, so the useful part is knowing which source signals are hardening and which ones still need caution. In security, the real value is whether the team becomes measurably safer, not whether another settings screen has been added.

Where the sources line up

The finding poses little to no practical threat in the immediate term, except possibly in a few edge cases. Even applying the attack against the deprecated use of 1024-bit keys, the method requires more computation than just about anybody—short of nation-states or companies with massive resources—can achieve. Widely used RSA implementations are also safe. In security, the real value is whether the team becomes measurably safer, not whether another settings screen has been added. The people who should read carefully are system admins, shop owners, content teams, and anyone holding customer data or operational accounts.

Practical impact for readers

Nonetheless, the research has taken cryptographers by surprise because it introduces signature forgery, a new way to break RSA keys without factoring. Equally important, this novel method reduces the required computing resources by orders of magnitude. The people who should read carefully are system admins, shop owners, content teams, and anyone holding customer data or operational accounts. The next step is to see whether the current signals harden into a durable change or fade as a short-lived experiment.

Who should pay attention now

“If this result holds up under peer review, it would indeed be a conceptual break-through,” Karsten Nohl, a cryptography expert and the head of innovation at Allurity, said in an interview. “RSA is as difficult to break as it is to factor large integers, at least so we thought. The researcher suggests that you can practically break RSA without cracking its key.

What is still unclear

Cryptographers thought that the only way to compute valid RSA digital signatures was to first compute the private key by factoring, and then use the private key to compute the signatures. For 1024-bit RSA, this was thought to be very expensive, albeit probably doable if you have the computational resources of the large tech companies or the NSA—on the order of tens of millions of dollars of computation time for a single key. For 2048-bit RSA, it was thought to be totally out of reach.

Source notes

Related stories

SecurityHumans, not rogue AI, are still the biggest cybersecurity risk to energy systemsSecurityWindows 11’s next security feature may cost you gaming performanceSecurityEnterprise AI transformation relies on the end-to-end platform: Azure was built for this moment