San DiegoForging an RSA signature took 1,380 core-years.
The attack cuts 1024-bit RSA security from 2^80 operations to 2^65 without factoring the key.
It runs a special number field sieve against a signing oracle, so it works only on blind-signature, or textbook, RSA.
The authors stress that RSA using PKCS or PSS padding, the overwhelming majority, is not exposed.
Privacy Pass, used by Apple and Cloudflare, is the best-known target, needing 2^43 signatures from a compromised server.
How each outlet framed it
- Ars Technica
- details attack feasibility: generating 243 signatures equals Cloudflare's daily traffic, keys rotate but don't eliminate risk
Sources: Ars Technica