2 comments

  • theamk 3 hours ago

    relevant parts from linked repo:

    > The algorithm only works if a raw signing oracle is available. Most RSA usage in practice (that is, RSA signatures using PKCS#1v1.5 or RSA-PSS padding) do not expose such an oracle, and thus this attack does not pose a practical risk. Examples of RSA use that do expose such a signing oracle would include blind RSA signatures (e.g. Privacy Pass) or HSM APIs.

    > Are people actually still using RSA?

    > Yes, particularly for digital signatures (e.g. certificates, TLS handshakes, tokens, OAuth). Key exchange for protocols like TLS uses ECDH or has transitioned to ML-KEM, and the attack does not apply to these algorithms.

    This is breaking only some rare kinds of RSA usage... And if you are considering new system that uses RSA signatures, please don't. Use elliptic curves - the operations are faster, the signatures and keys are smaller, and there are fewer attacks.

    Even PrivacyPass stopped using RSA signatures for that reason [0], which means that the only example of applicable technology is no longer correct.

    [0] https://blog.cloudflare.com/privacy-pass-the-math/#previousl...

  • ChrisArchitect 2 hours ago