Not RSA-1024 factorization: cryptographer explains it's a 2007 signature forgery attack
matthew_d_green · x · 2026-09-22
Cryptographer Matthew Green clarifies that the recent RSA-1024 headline is not a factorization breakthrough. It's an implementation of a 2007 attack by Joux, Naccache and Thomé: given an oracle (a "lunchtime attack") computing m^d mod N for arbitrary unpadded messages, an attacker can forge signatures on chosen messages after many oracle queries and heavy computation. The risk stems from unsafe implementations, not a break of RSA itself.
Related event: UCSD Researchers Forge 1024-bit RSA Signatures Near SNFS Time(3 posts)→
More from Safety
- Muse Mac AI agent has 0-day flaws that turn it into 'the ultimate backdoor', researcher warns — nptacek · 2026-09-22
- Exabeam exec: hardest AI security problems now live outside the model — virtualsteve · 2026-09-22
- Automated reinforcement learning should scare you: from AlphaGo to math to bio labs — hattusili-the-third · 2026-09-22
- Stanford Accused of Using AI to Alter Students' Race and Gender in Ads — Polymarket · 2026-09-22
- ChatGPT reportedly refuses simple questions unless users grant email access — RexDouglass · 2026-09-22
- OpenAI calls for US leadership in setting global AI standards — Anxious-Yoghurt-9207 · 2026-09-22