‹ BackHN Continuity

Thread

Forging 1024-bit RSA signatures in nearly SNFS time [pdf]

72 points · 22 comments · int0x29

  1. xeyownt · · focus · HN ↗
    "It does, however, drastically lower the estimated security of RSA, and it does so in a way no one knew of previously"

    Wrong.

    Multiplicative structure of RSA is known since it was invented, and that's exactly why standard like PKCS were created. This attack is NOT applicable to these standards (as said in the article). Author shows a poor understanding of the field.

    Using RSA blinding signatures is like using windows 95 and connect it directly to the internet.

Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.