Not RSA-1024 factorization: cryptographer explains it's a 2007 signature forgery attack

matthew_d_green · x · 2026-09-22

Cryptographer Matthew Green clarifies that the recent RSA-1024 headline is not a factorization breakthrough. It's an implementation of a 2007 attack by Joux, Naccache and Thomé: given an oracle (a "lunchtime attack") computing m^d mod N for arbitrary unpadded messages, an attacker can forge signatures on chosen messages after many oracle queries and heavy computation. The risk stems from unsafe implementations, not a break of RSA itself.

Related event: UCSD Researchers Forge 1024-bit RSA Signatures Near SNFS Time(3 posts)→

Original post →

More from Safety

Safety channel →