The world has known for decades that the RSA cryptosystem’s days are numbered. Once quantum computing becomes practical (estimates for that range from 3 to 20 or more years), the foundational security it provides will crumble. New research has revealed a novel method that uses classical computing to reduce the current RSA security level to an unacceptably low threshold.
The finding poses little to no practical threat in the immediate term, except possibly in a few edge cases. Even applying the attack against the deprecated use of 1024-bit keys, the method requires more computation than just about anybody—short of nation-states or companies with massive resources—can achieve. Widely used RSA implementations are also safe.
Nonetheless, the research has taken cryptographers by surprise because it introduces signature forgery, a new way to break RSA keys without factoring. Equally important, this novel method reduces the required computing resources by orders of magnitude.
Does this mean I should upgrade my encryption right now? The article says wait, but ‘orders of magnitude’ scares me.
Still think we are overreacting. If it requires nation-state resources, my 2048-bit keys are safe for now.
I thought quantum computers were the only threat? This classical method breaking signatures is genuinely surprising news.