Researchers from UC San Diego and France’s INRIA forged RSA signatures on a 1,024-bit key inside a hardware security module without ever extracting the private key. The attack required roughly 4 billion signature requests and 1,380 CPU core-years, and the researchers had to disable the module’s certified FIPS mode to sign unformatted numbers. This oracle-based technique only applies to unpadded RSA signatures and poses no immediate threat to Bitcoin or Ethereum, which use elliptic-curve signatures. The authors present the result as classical evidence supporting the abandonment of RSA during the post-quantum cryptography transition.
Source: Read the original article

