Forgot your password?
typodupeerror

Submission + - Researchers Found a New Way to Break RSA that Doesn't Require Factoring the Key (cybersecuritynews.com)

An anonymous reader writes: Security researchers have demonstrated a faster way to undermine certain RSA deployments without factoring the public modulus, challenging the assumption that RSA’s practical strength always tracks the cost of integer factorization.

The attack converts temporary access to a raw, unpadded RSA signing or decryption service into a lasting capability to forge signatures or decrypt chosen ciphertexts offline.

Laura Shea, Miro Haller, Adam Suhl, Nadia Heninger and Emmanuel Thomé implemented the technique against a 1,024-bit RSA key. Their computation consumed 1,380 CPU core-years over five months and required 232 oracle queries. By comparison, factoring a 1,024-bit RSA modulus is estimated to require roughly 500,000 to one million core-years.

The method, called eNFS by the researchers, belongs to the number field sieve family. Instead of the general number field sieve used to factor RSA moduli, it approaches the faster “special” number field sieve complexity by replacing part of the usual mathematical work with answers from the signing oracle. Crucially, it never recovers the prime factors or RSA private key.

The attack unfolds in stages. An approximately 1,200-core-year precomputation depends only on the public modulus and exponent. The attacker then submits selected values to the raw RSA oracle. Once those responses are collected, access can disappear: forging any chosen signature or decrypting a target takes about another 180 core-years and can be repeated offline.

The underlying algorithm is not new. Antoine Joux, David Naccache and Emmanuel Thomé introduced it in 2007, but the new work provides its first implementation and large-scale 1,024-bit demonstration. The code builds heavily on CADO-NFS while adding the engineering needed for polynomial selection, sieving, linear algebra, root extraction, and descent at this scale.

This is not a universal RSA break. The attacker needs temporary access to a raw exponentiation oracle, a capability that conventional RSA signatures using PKCS#1 v1.5 or RSA-PSS padding normally do not expose. More plausible targets include HSM interfaces permitting raw PKCS#11 RSA operations and blind-signature protocols such as Privacy Pass, where blinded requests can provide the required oracle behavior.

The researchers estimate 2^{90} work and 2^{43} oracle queries against 2,048-bit RSA in this model, versus the commonly assigned 112-bit factoring strength. They project roughly 2^{119} work for 4,096-bit RSA, leaving it short of a modern 128-bit security target. Those costs remain beyond attackers, but could matter to well-resourced adversaries and protocols with long-lived public keys.

Organizations do not need to abandon correctly padded RSA immediately. Operators should disable unnecessary raw RSA mechanisms, audit HSM policies, limit oracle exposure, and rotate vulnerable blind-signature keys more frequently.

Protocol designers can investigate zero-knowledge proofs of well-formed requests, while longer-term migration should favor modern signature schemes and post-quantum cryptography rather than treating larger RSA keys as a permanent solution.

Submission + - SourceHut changes terms of service limiting LLM use (sourcehut.org)

bjoast writes: The SourceHut Git hosting provider recently changed its terms of service to limit how users may make of use of LLMs in their work, citing resource constraints and ethical concerns. From the the new terms of service:

The new terms of service, which will go into effect for new projects after the usual two week notice period (i.e. September 10th), will now include the following under the list of prohibited content:

  • original content written with or which facilitates the use of LLMs (large language models) or other generative AI technologies

The use of LLMs or other generative AI tools to produce or assist with the production of source code, assets, tickets, emails, and so on, will no longer be permitted on SourceHut once these terms take effect. As with our other policy changes, the intention is to roll this out slowly and thoughtfully. Each possible violation will be evaluated on a case-by-case basis and we are open to making exceptions.


Comment Traditional Search has long been useless (Score 1) 85

The results that come first aren't there because they're useful, but because the site's owners have gamed the algorithm to come first, and then surrounded that algo-gaming content with as many tangibly related advertisements as possible in the hope of generating some cash.

Having an LLM help parse through the bollocks has been a refreshing experience, honestly.

Comment Re:Headline could be repeated every year (Score 1) 24

WordPress, usually, is 'good enough' for most SMEs that need something with editing capability; but nothing with any hugely complicated business or ecommerce logic.

For the agency I work for, WordPress is our default entry-level platform for SMEs that don't need ecommerce or complex custom development. It is *considerably* better than it was 10 years ago.

Submission + - Californians sign up to have data brokers delete their personal information (eastbaytimes.com)

ZipNada writes: More than 300,000 Californians have demanded that hundreds of data brokers erase information about their locations, finances, health and personal lives as the state’s first-in-the-nation Delete Act requires brokers to start the mandatory process of removing data on Aug. 1.

Brokers must start accessing deletion requests within 45 days after Aug. 1, then once they have collected those requests, they have another 45 days to report what data they have purged to the agency — known as CalPrivacy — and people who have signed up. ...
The information Californians are asking brokers to erase can be extraordinarily sensitive. Of the nearly 600 data brokers in CalPrivacy’s registry, 110 sell people’s precise locations, the registry shows. More than 40 sell identity data that can include Social Security numbers. Almost 70 sell information on people’s gender identity. Seven sell data related to reproductive health, and six sell information on union membership. Eighteen sell minors’ data — and Kemp said children can sign up for deletion using DROP, or parents can do it for them.

Many of the brokers build — and sell to advertisers and marketers — dossiers that are increasingly processed using artificial intelligence to draw conclusions about a person’s interests, family, politics, lifestyle, finances, sexual orientation and health.

Submission + - Firefox 152 Adds JPEG XL Support, Redesigned Settings (linuxiac.com)

An anonymous reader writes: Mozilla has released Firefox 152, the latest update to its popular open-source web browser, with updated settings, improved media controls, experimental JPEG XL support, and various platform-specific fixes for desktop and Android. A key update is the redesigned Firefox Settings page, which now features clearer groupings, improved navigation, and a more streamlined structure for easier customization. The release also expands built-in spellchecker support, adding dictionaries for Croatian, English (UK), Georgian, Persian, Slovenian, Tajik, Tamil, Tibetan, Turkish, Welsh, and Xhosa. [...] Importantly, Firefox now offers experimental support for JPEG XL, an image format with improved compression over WebP, JPEG, PNG, and GIF. Users can enable JPEG XL in the Firefox Labs panel within Settings.

Submission + - Humans prefer to walk anticlockwise (theguardian.com)

fjo3 writes: Tests reveal that when people are ambling about, they have a natural tendency to turn to the left and walk in an anticlockwise direction.

“If you simply ask someone to start walking, whether they are wandering around a museum, a supermarket, or even an empty room, it is surprisingly likely that they will drift counterclockwise,” said Dr Iñaki Echeverría Huarte at University of Navarra in Spain.

Submission + - R.I.P. Code.org (2013–2026)

theodp writes: This week saw tech-backed K-12 CS education nonprofit Code.org rebrand itself as CodeAI (press release), solidifying its shift to AI education more than a decade after it launched in 2013 with the belief "that every student should learn the basics of computer programming." Of the AI rebranding, Code.org Founder and Chairman of The Board Hadi Partovi explained, "We have a responsibility to prepare the next generation for the biggest change In society since the invention of public education."

Following the announcement, members of the Code.org Advocacy Coalition were informed in a conference call that the nine-year-old coalition was being sunsetted immediately. Members will be asked to decide if they want to join a new CodeAI Advocacy Coalition, which will be "bringing in new AI focused entities that will help us advance this mission", or if they are "not in line with the direction that CodeAI is heading" and are "not going to be part of the new advocacy coalition." Much like their tech giant donors, the message sent was it's the AI way or the highway.

Interestingly, the pivot from CS education to AI literacy comes amid reports that blamed increased reliance on AI for causing more than 35% of UC Berkeley students to fail an entry-level CS course described as "a gentle but thorough introduction to computer science," when previously the failing rate was typically 7%.

Submission + - Astronauts return to ISS after sheltering during air leak repair attempt (bbc.com)

fjo3 writes: Astronauts on the International Space Station (ISS) were ordered to shelter in an attached spacecraft after the structure suddenly started leaking more air.

Five of the seven crew were directed to go into the docked SpaceX shuttle Dragon "Freedom" on Friday afternoon and were braced for a potential evacuation.

Meanwhile, two remaining personnel — a pair of Russian cosmonauts — attempted to repair a part of the Russian segment of the ISS, where the leaks had started increasing on Monday.

The repairs were paused and the crew ordered back onto the ISS by Nasa on Friday afternoon.

Submission + - NASA admits mismanagement and human errors caused 2025 Goldstone antenna damage (behindtheblack.com)

schwit1 writes: NASA today released its completed investigation into the November 2025 incident that severely damaged its Goldstone antenna in California when workers allowed the antenna to "over rotate" beyond its acceptable limits, putting it out of commission.

You can read that report here [pdf], but be warned that large sections are redacted, apparently in an effort to protect the identities of those responsible.

Nonetheless, it is very clear that the management and work situation at Goldstone was a mess, and that the mishap was caused not by faulty engineering but by faulty work practices and bad management. Unfortunately, nowhere in the report is it said that there will be any management changes. This fact might have been redacted, but I suspect not. It is typical of government agencies like NASA after incidents like this to whitewash the investigation, concluding simply that "we should have done better and we now we will!"

The repairs will cost NASA about $4.6 million, and will likely not be completed until 2028.

Slashdot Top Deals

"The way of the world is to praise dead saints and prosecute live ones." -- Nathaniel Howe

Working...