Forgot your password?
typodupeerror

Comment Re:Offtopic (Score 1) 18

I'm actually interested in what they plan to do about Wedge Tailed eagles. I remember as a kid losing kites to those monsters, they are very territorial during breading season. For those that don't know how big they are, from Wikipedia: "it has a maximum reported wingspan of 2.84 m (9 ft 4 in) and a length of up to 1.06 m (3 ft 6 in)."

Submission + - Researchers Found a New Way to Break RSA that Doesn't Require Factoring the Key (cybersecuritynews.com)

An anonymous reader writes: Security researchers have demonstrated a faster way to undermine certain RSA deployments without factoring the public modulus, challenging the assumption that RSA’s practical strength always tracks the cost of integer factorization.

The attack converts temporary access to a raw, unpadded RSA signing or decryption service into a lasting capability to forge signatures or decrypt chosen ciphertexts offline.

Laura Shea, Miro Haller, Adam Suhl, Nadia Heninger and Emmanuel Thomé implemented the technique against a 1,024-bit RSA key. Their computation consumed 1,380 CPU core-years over five months and required 232 oracle queries. By comparison, factoring a 1,024-bit RSA modulus is estimated to require roughly 500,000 to one million core-years.

The method, called eNFS by the researchers, belongs to the number field sieve family. Instead of the general number field sieve used to factor RSA moduli, it approaches the faster “special” number field sieve complexity by replacing part of the usual mathematical work with answers from the signing oracle. Crucially, it never recovers the prime factors or RSA private key.

The attack unfolds in stages. An approximately 1,200-core-year precomputation depends only on the public modulus and exponent. The attacker then submits selected values to the raw RSA oracle. Once those responses are collected, access can disappear: forging any chosen signature or decrypting a target takes about another 180 core-years and can be repeated offline.

The underlying algorithm is not new. Antoine Joux, David Naccache and Emmanuel Thomé introduced it in 2007, but the new work provides its first implementation and large-scale 1,024-bit demonstration. The code builds heavily on CADO-NFS while adding the engineering needed for polynomial selection, sieving, linear algebra, root extraction, and descent at this scale.

This is not a universal RSA break. The attacker needs temporary access to a raw exponentiation oracle, a capability that conventional RSA signatures using PKCS#1 v1.5 or RSA-PSS padding normally do not expose. More plausible targets include HSM interfaces permitting raw PKCS#11 RSA operations and blind-signature protocols such as Privacy Pass, where blinded requests can provide the required oracle behavior.

The researchers estimate 2^{90} work and 2^{43} oracle queries against 2,048-bit RSA in this model, versus the commonly assigned 112-bit factoring strength. They project roughly 2^{119} work for 4,096-bit RSA, leaving it short of a modern 128-bit security target. Those costs remain beyond attackers, but could matter to well-resourced adversaries and protocols with long-lived public keys.

Organizations do not need to abandon correctly padded RSA immediately. Operators should disable unnecessary raw RSA mechanisms, audit HSM policies, limit oracle exposure, and rotate vulnerable blind-signature keys more frequently.

Protocol designers can investigate zero-knowledge proofs of well-formed requests, while longer-term migration should favor modern signature schemes and post-quantum cryptography rather than treating larger RSA keys as a permanent solution.

Submission + - CATL launches 170 Wh/kg modular, heavy-duty vehicle battery w/621 mile range (interestingengineering.com)

fahrbot-bot writes: Interesting Engineering is reporting that the Chinese battery company CATL has unveiled its next-generation modular commercial vehicle battery platform, TECTRANS II, at IAA Transportation 2026 in Hanover.

Rather than a basic cell update, the system is a adaptable modular architecture that integrates into existing vehicle lines. Truck manufacturers can achieve up to 1,000 kilometers (621 miles) of range on a single charge, backed by megawatt-level fast charging that replenishes 80% capacity in 25 minutes.

The battery delivers a gravimetric energy density of 170 Wh/kg, exceeding the industry average by 13% and increasing payload capacity by 0.6 tonnes.

CATL rates the heavy-duty truck setup for a 12-year, 1.5-million-kilometer (932,056 mile) operating lifecycle while retaining 70 percent capacity.

Submission + - New RSA attack takes cryptographers by surprise (arstechnica.com)

phatrabt writes: There’s a new way to break RSA that’s faster than anything we’ve seen before Until now, cryptographers thought factoring was the only way to break RSA. Not anymore.

“If this result holds up under peer review, it would indeed be a conceptual break-through,” Karsten Nohl, a cryptography expert and the head of innovation at Allurity, said in an interview. “RSA is as difficult to break as it is to factor large integers, at least so we thought. The researcher suggests that you can practically break RSA without cracking its key.”


Submission + - More Than One in Five "Hi-Res" Audio Discs Are Just the CD, Tests Find (losslessextract.com)

packslash writes: Summary: The developer of Lossless Extract, built a detector for upsampled audio and has run it on 1,225 SACD, DVD-Audio and Blu-ray Audio discs anonymously from users' collections. 272 of them, 22 percent, failed. "They hold CD-quality audio, no better than the $10 CD, stretched to fit a bigger disc and sold back at triple the price," the developer writes. The failures include Prince's Purple Rain on Blu-ray, Rush's Moving Pictures and Dave Brubeck's Time Out. The test looks for music that stops dead at the CD's ceiling, with a silence above it "so perfect it can't happen in the real world." Results depend on the edition. The 2003 SACD of Norah Jones' Come Away With Me fails, while the 2012 SACD made from the analog tapes passes. The full list is public, and readers can test their own files in the browser without uploading anything.

Verify Hi res site https://ancillary-proxy.atarimworker.io?url=https%3A%2F%2Flosslessextract.com%2Fve...

Submission + - Steam's Unofficially Official ARM Client For Linux (interfacinglinux.com)

VennStone writes: Steam for ARM has been publicly available for a little over five months, and a recent update clicked all the bits into place needed to run the FEX emulator with Proton (ARM64) out of the box. So now seems like a good time to find out how well the unofficially official client works with a couple of Frame-verified games and a couple that, well, have no business running on ARM.

Submission + - Trump says Arch will be a military complex with weapons, drones, sniper's nest (theguardian.com)

fahrbot-bot writes: The Guardian is reporting, along with others, that President Donald Trump is proferring a new argument for building his triumphal arch in Washington DC: it will be converted into a “top grade military complex” replete with drone and ammunition storage space and customized sniper facilities on the roof and plaza.

In a post on his Truth Social platform on Sunday morning, Trump claimed that his new plan came at the “strong request” of the US military. He said the 250ft structure would be able to “house, store, and have the rapid ability to use large quantities of sniper ammunition in storage”. The president added, “There will be no facility like this anywhere in the world.”

This seems like a ploy to get around courts holding up the project by re-framing the project as a National Security matter, as he did with the East Wing of the White House. (Can the Kennedy Center be far behind?)

Submission + - America PAC's VoteSafe.org is nothing but a honeypot (cybernews.com)

echo123 writes: Elon Musk’s bogus voter registration website is collecting extensive user data and selling it.

The website was funded by Musk and is operated by America PAC, a conservative political action committee founded in 2024 to support Donald Trump’s presidential campaign.

The VoteSafe.org website has been promoted as a way for Americans to register to vote and check their registration ahead of the November midterm elections.

But MeidasTouch and Snopes found that despite presenting itself as a voter-registration resource, the site doesn’t actually register users to vote.

The site's privacy policy says America PAC can collect information, including:

        Users' names
        Dates of birth
        Addresses
        Email addresses
        Phone numbers
        IP addresses
        Location
        Information about how they interact with the site

It also permits the collection of "inferences" about users, including their preferences, characteristics, behavior, attitudes, and psychological tendencies.

The policy says the information may be shared with or sold to business partners for targeted marketing.
 

Comment Re:Is this really what people will pay for? (Score 3, Interesting) 183

I actually pay for Nitro. There is only one feature that I want, and its to be able to stream at a decent quality. I have friends scattered all over the world who also use discord. Almost everyday I'm streaming something on discord, so its worth it to me just for the streaming quality improvement. I'd love a cheaper option without all the rest of nitro, that stuff doesn't make any sense to me.

Comment Re:maybe the low paid rent a cops took them. You k (Score 1) 34

I used to work our company booths at many different events for many years. Every event I went to, someone at the company told all of us, that "All equipment must be secured at all times". Every computer/laptop we had, would have at least a security cable locking it to our table. None of the computers were allowed to be left at the booth unless someone was physically present.

I'm shocked that anyone would think "out of sight, out of mind" would be a good security choice. What doesn't surprise me at all, is the event saying "not our fault, read the T&Cs".

Slashdot Top Deals

Asynchronous inputs are at the root of our race problems. -- D. Winker and F. Prosser

Working...