RSA Signature Forgery Demonstrates Security Concerns in Crypto Key Custody
- Researchers at UC San Diego and France’s INRIA successfully forged RSA signatures on a hardware security module without extracting the key.
- The attack required about \(2^{32}\) signing requests (approximately four billion) and took an estimated 1,380 CPU core-years to execute.
- Bitcoin and Ethereum use elliptic-curve signatures like ECDSA, not RSA, so they remain unaffected by this vulnerability.
- The paper suggests no immediate threat to modern RSA deployments that utilize padding techniques like PKCS#1 v1.5 or PSS.
- This research highlights the need for transitioning away from RSA in preparation for post-quantum cryptography.
Researchers demonstrated the ability to forge RSA signatures within a hardware security module, emphasizing potential vulnerabilities in crypto key custody systems despite using secure devices. While this does not affect Bitcoin or Ethereum, it underscores the importance of moving towards quantum-resistant encryption methods as part of future-proofing strategies.
The study serves as a reminder of the evolving landscape of cryptographic security and the necessity for ongoing adaptation to emerging threats, particularly with quantum computing on the horizon. (Source)