The assumption that RSA encryption broken by classical machines was practically impossible — that only a quantum computer powerful enough to run Shor's algorithm could threaten the cryptosystem — has held for decades. New research published in September 2026 has quietly upended that assumption, and the cryptography community is still processing what it means.
What Researchers Just Discovered About RSA Security
RSA, the public-key cryptosystem invented by Rivest, Shamir, and Adleman in 1977, secures everything from TLS certificates to digital signatures. Its security rests on a deceptively simple idea: multiplying two large prime numbers together is trivial, but reversing the operation — finding the original primes from the product — is computationally brutal at sufficient key lengths. For years, "sufficient" meant anything at or above 2048 bits.
The new research introduces a classical computing method that, applied to 1024-bit RSA keys, completed its attack over a period of months on an ordinary academic CPU cluster. That timeline is striking. Before this work, breaking a 1024-bit RSA key was considered a task requiring resources at the scale of a nation-state intelligence apparatus or a technology company with extraordinary computational infrastructure. The researchers did it with equipment a well-funded university department could reasonably assemble.
The resource reduction is described as several orders of magnitude — not a modest improvement, but a structural leap in what is tractable for well-resourced non-state actors. That shift matters even if the target keys are already deprecated, because deprecation in cryptography rarely means instant retirement in practice.
Signature Forgery: A New Way to Break RSA Without Factoring
Here is the detail that genuinely surprised cryptographers: the attack does not work by factoring the RSA modulus. For decades, the implicit model for attacking RSA was that breaking it meant factoring the product of two large primes. Enormous research effort has gone into making that harder — the number field sieve, lattice reduction techniques, distributed factoring projects. The entire architecture of RSA key-length recommendations was built around the assumption that factoring was the attack surface.
Read next Laika's Wildwood: Stop-Motion Fantasy at TIFF 2026This new work bypasses factoring entirely. Instead, it achieves signature forgery — the ability to produce cryptographically valid signatures without ever possessing the private key, and without recovering the underlying primes. That distinction is not merely academic. It means the community's collective hardening work against factoring-based attacks did not anticipate or block this vector.
The surprise within the research community is itself a signal worth noting. Cryptographers are not easily startled. When a field populated with researchers who spend careers stress-testing mathematical assumptions collectively registers that something unexpected has arrived, that reaction carries evidentiary weight. The signature-forgery vector represents a conceptually new seam in RSA's security model, one that opens a separate line of attack independent of everything the field has built to resist factoring.
How Dangerous Is This Attack in Practice?
The practical risk is real, but calibrated. Two factors contain the immediate damage.
First, the attack targets 1024-bit keys. NIST deprecated those keys in 2013, more than a decade ago, on the grounds that advances in factoring algorithms and computational hardware had already made them inadequate for long-term security. Any organization following current NIST guidance — which recommends a minimum of 2048-bit keys for RSA and encourages 3072-bit or 4096-bit keys for data requiring long-term protection — is not directly exposed to this specific attack. Modern TLS deployments, certificate authorities operating under the CA/Browser Forum baseline requirements, and software using up-to-date cryptographic libraries are all working with key lengths well beyond 1024 bits.
Second, widely used RSA implementations are described by the researchers as currently safe. The attack has not been demonstrated against the key sizes in active deployment across the internet's core infrastructure.
But "not immediately dangerous" is not the same as "not significant." An attack that reduces the resources required to break a key size from nation-state level to academic-cluster level is moving a threshold that people assumed was fixed. And the more consequential concern is what the signature-forgery method implies for larger key sizes as the technique matures or is extended. The 1024-bit result is a proof of concept that something previously assumed implausible is now demonstrably achievable with modest resources.
What This Means for the Future of RSA Encryption
Consider the trajectory. In the early 2000s, breaking a 512-bit RSA key was a multi-year project for a well-funded team. By the mid-2000s, it was achievable in weeks. NIST's 2013 deprecation of 1024-bit keys reflected the recognition that the computational bar for attacking those keys had dropped within range of sophisticated adversaries. The new research suggests the 1024-bit bar has now dropped further — into the range of a committed academic group with cluster access.
If that pattern holds, the question for 2048-bit keys is not whether they will eventually face analogous pressure, but when. The signature-forgery approach introduces a new line of attack that the community will now examine aggressively for extension to larger moduli. Research that surprises the field once tends to spawn follow-on work that extends its reach.
This is precisely why NIST launched its post-quantum cryptography standardization process years ago. In 2024, NIST finalized its first set of post-quantum cryptographic standards, including CRYSTALS-Kyber for key encapsulation and CRYSTALS-Dilithium for digital signatures, algorithms designed to resist both quantum and classical adversaries. The new research, ironically, reinforces the urgency of that transition even before quantum computers arrive.
Should You Be Worried? Practical Implications for Businesses and Users
For most users, the honest answer is: not urgently, but pay attention. If you are using a modern browser, a current operating system, or any software that received security updates in the past several years, the RSA keys protecting your connections are almost certainly 2048 bits or larger. This attack does not touch those implementations.
The organizations with a more immediate reason for concern fall into two categories. The first is anyone still running legacy systems that generate or rely on 1024-bit RSA keys. Industrial control systems, older VPN appliances, legacy authentication infrastructure, and certain embedded devices can fall into this category. Those environments should treat this research as an urgent prompt to complete transitions that NIST's 2013 deprecation already recommended.
The second category involves long-lived data. Cryptographic secrets encrypted today under RSA keys that will remain in service for years or decades face a different threat model than ephemeral session keys. If the underlying method extends to larger key sizes — a possibility the research raises even if it does not demonstrate it — data encrypted now could be vulnerable later. The "harvest now, decrypt later" strategy, already a concern in the quantum computing threat model, applies here too.
The concrete, actionable guidance has not changed significantly from what NIST has been recommending: move toward post-quantum algorithms for new systems, audit legacy deployments for deprecated key sizes, and prioritize the elimination of 1024-bit RSA wherever it persists.
The Broader Shift Toward Post-Quantum Cryptography
RSA has dominated public-key cryptography for nearly half a century because its mathematics are well understood, its implementations are mature, and its track record of resisting attack has been reassuring. That reassurance is now meaningfully reduced — not shattered, but chipped in a way that accelerates a transition already underway.
The quantum computing threat to RSA is real and broadly understood: a sufficiently powerful quantum computer running Shor's algorithm could factor RSA keys in polynomial time. Current estimates for when such a machine arrives range from roughly three years on the optimistic end to two decades or more for skeptics. The post-quantum cryptography effort was built around that threat.
What the 2026 research introduces is a different kind of pressure. It demonstrates that classical computing advances can also erode RSA's security margins, and that those advances can arrive through conceptually novel routes — signature forgery rather than factoring — that the field did not fully anticipate. The combination of a maturing quantum threat and a newly demonstrated classical attack path is a compelling argument for treating the migration to post-quantum algorithms as an active operational priority rather than a distant planning exercise.
The death of RSA encryption broken by classical machines was not supposed to happen before quantum computers arrived. This research suggests the timeline is more complicated, and more compressed, than the field assumed.
Source: Ars Technica - All content



