In brief: A research team forged arbitrary RSA-1024 signatures without factoring the public modulus or extracting the private key. The record substantially lowers the assumed security of specific RSA applications. Ordinary TLS and Web PKI signatures are unaffected because the attack requires temporary access to a raw, unpadded RSA oracle.
Confirmed: 1,380 core-years and 232 oracle queries
Laura Shea, Miro Haller, Adam Suhl, Nadia Heninger and Emmanuel Thomé implemented a 2007 attack using the special number field sieve. Over five months it consumed 1,380 CPU core-years: roughly 1,200 for public-modulus precomputation and 180 for the later forgery. The researchers made 232 raw RSA requests to HSMs between those stages, then created further signatures offline while the private key remained inside.
The paper estimates factoring RSA-1024 with current software at 500,000 to one million CPU core-years. The figures are not equivalent: the new attack was executed, whereas the factoring cost is estimated. The team also disabled the tested Luna K6 HSM's FIPS 140-2 mode to enable raw RSA.
Blind signatures are the relevant exception
The model matches blind RSA, where a client obtains a signature on a value the signer cannot inspect. RFC 9474 standardises it as RSABSSA; Privacy Pass and Apple Private Access Tokens are deployments examined in the paper. For RSA-2048, the authors estimate 290 work and 243 oracle queries. That is below the usual 112-bit rating, yet remains an enormous barrier.
For 4096-bit keys, the extrapolation reaches 2119 operations rather than 144–152 security bits inferred from factoring. These are not demonstrated attacks. Hidden constants, parameter improvements and extrapolation from the 1024-bit run add uncertainty.
Pandorex Analysis: “RSA is broken” would go too far
PKCS#1 v1.5 and RSA-PSS signatures used by TLS, certificates and many tokens do not expose the raw oracle. The paper finds no comparable speed-up over factoring for these padded schemes. Ars Technica explains this limit correctly, but its headline about a new way to break RSA is broader without that context.
Blind-RSA operators should compare key rotation and query limits with the 243-query scale. The paper proposes larger keys, zero-knowledge proofs of well-formed requests and eventually moving away from RSA. Conventional RSA signatures need no emergency migration, but the result supports existing post-quantum transition plans.
