‹ BackHN Continuity

Thread

Forging 1024-bit RSA signatures in nearly SNFS time [pdf]

72 points · 22 comments · int0x29

  1. nk_kolja · · focus · HN ↗
    I was unaware of snfs algorithms for generic moduli and/or signatures. Very nice. The theoretical result is purely due to the 2007 Joux et al. paper. What’s new is the implementation and the 1024-bit rsa signature forgery.

    Also no ai, so we can expect some speedups soon.

    I really didn’t expect rsa to be targeted so much this year. Hope that these results will motivate people to pursue algorithmic improvements!

Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.