TechBriefe
Tech Briefing

New Technique Bypasses 1,024-Bit RSA Without Factoring It

Tom McKay 02.10.2026

How the Signature Forgery Attack Works

Researchers from the University of California, San Diego and Inria Nancy have demonstrated a new method to forge digital signatures on 1,024-bit RSA encryption without needing to factor the underlying primes. The attack, detailed in a recent academic paper, reduces the computational effort required from an estimated 500,000 CPU core-years to just 1,380 CPU core-years. While still substantial, this represents a significant reduction in the resources needed to compromise this once-widely used cryptographic standard. The work highlights ongoing vulnerabilities in legacy systems still relying on 1,024-bit RSA keys.

Instead of attempting to factor the large semiprime number at the heart of RSA, the researchers exploited weaknesses in the padding scheme used during signature generation. By manipulating specific mathematical properties of the RSA algorithm under certain conditions, they were able to produce valid-looking signatures without knowing the private key. This approach shifts the attack vector from number theory to implementation-level flaws in cryptographic protocols. The technique requires precise conditions but proves feasible with moderate computational resources compared to brute-force factoring.

What Does This Mean for Real-World Security?

Although 1,024-bit RSA is considered outdated and has been phased out in favor of 2048-bit or higher keys, many legacy systems, embedded devices, and older software still depend on it. The reduced cost of attack increases the risk for organizations that have not fully migrated away from these weaker keys. Experts warn that even if the attack is not immediately practical for widespread use, it undermines confidence in the long-term security of RSA and emphasizes the need for timely cryptographic upgrades. Continued reliance on deprecated standards could expose critical infrastructure to future exploits.

Frequently Asked Questions

Is 1,024-bit RSA still in use today? Yes, while deprecated for years, some legacy systems, industrial equipment, and outdated software continue to rely on 1,024-bit RSA due to slow update cycles or compatibility constraints.

Does this mean RSA is completely broken? No, the attack does not break RSA in general or affect properly implemented 2048-bit or stronger keys. It specifically targets weaknesses in certain signature implementations of smaller key sizes, not the core algorithm itself.

Share:

More stories: