Novel attack slashes computing power needed to crack textbook RSA cryptography
What happened
The paper outlines a new attack that breaks RSA in record time. That's concerning because RSA-based encryption was in use for quite some time, and although it's been generally deprecated in favor of ECC and post-quantum algorithms , it's still employed today in a substantial portion of services.
Equipment and services using PKCS #11, like many smart cards, USB security tokens, code-signing pipelines, hardware security (HSM) and trusted platform (TPM) modules also use this variation. But fulfilling the attack conditions is much easier said than done.
In order to reach a point where an attacker can decipher data, they first must perform an exceedingly high number of queries against the key they're attacking, collecting enough data points from the key's oracle. In practical terms, this often means repeatedly poking a live server that's using that key to encrypt traffic, billions of times over, though it can also be done against a standalone hardware device.
Sources & evidence
- Tom's Hardware Reporting source
Novel attack slashes computing power needed to crack textbook RSA cryptography ↗
https://www.tomshardware.com/tech-industry/cyber-security/novel-attack-on-rsa-cryptography-might-bring-computation-requirements-for-cracking-down-to-manageable-levels