commit 1cf05d9f11d4f66ca904424700d933c84cad9898
parent e02f0bfdc398c99a24fe83046beb6b726b961dc7
Author: Özgür Kesim <oec@codeblau.de>
Date: Sun, 27 Sep 2026 14:52:19 +0200
[2026-12] more clear exposition how Taler is affected by the attacks against RSA-1024
Diffstat:
1 file changed, 42 insertions(+), 13 deletions(-)
diff --git a/template/news/2026-12.html.j2 b/template/news/2026-12.html.j2
@@ -1,21 +1,50 @@
{% extends "common/news.j2" %}
{% block body_content %}
-<h1>2026-09-27: {{ _("Forging 1024-bit RSA signatures in nearly SNFS time") }}</h1>
+<h1>
+Successful attacks against 1024-bit RSA signatures</h1>
<p>
- Laura Shea, Miro Haller, Adam Suhl, Nadia Heninger, and Emmanuel Thomé published
- a <a href="https://eprint.iacr.org/2026/2131">report</a> on implementing and
- successfully executing a not so well-known attack to forge RSA-1024 signatures
- by Joux, Naccache, and Thomé from 2007. The attack applies in principle to
- the blind signatures used by GNU Taler and as far as we know is the most
- efficient forgery attack on RSA signatures today. So we've never recommended
- using RSA-1024 and the academic attack is rather expensive, it still makes sense to
- analyze it to derive what its implications are on how one should configure
- a GNU Taler exchange, after all forging RSA signatures would enable an
- attacker to print money and bankrupt Taler exchange operators!
- What follows is a coarse back-of-the-envelope rough extrapolation of the cost
- of the attack against the standard GNU Taler configuration.
+ Laura Shea, Miro Haller, Adam Suhl, Nadia Heninger, and Emmanuel Thomé
+ published a report <a href="https://eprint.iacr.org/2026/2131">
+ <i>"{{ _("Forging 1024-bit RSA signatures in nearly SNFS time") }}"</i></a>
+ on implementing and successfully executing a not so well-known attack to
+ forge RSA-1024 signatures by Joux, Naccache, and Thomé from 2007. The attack
+ applies in principle to the blind signatures used by GNU Taler and as far as
+ we know is the most efficient forgery attack on RSA signatures today.
</p>
+<h2>Effects on Taler</h2>
+<p>
+ Any real and recommended deployment of GNU Taler
+ is not at risk from this attack,
+ due to the following security measures in GNU Taler:
+ <ul>
+ <li><b>Secure defaults:</b>
+ Taler's default minimal security level is RSA-2048,
+ which makes the attack <i>economically</i> infeasible in practice.
+ </li>
+ <li><b>Key rotation:</b>
+ Taler supports key rotation of demonination keys,
+ with a default of once per week,
+ which makes the attack <i>technically</i> infeasible in practice.
+ </li>
+ <li><b>Alternative to RSA available:</b>
+ Taler supports blind signatures of type Clause-Schnorr—introduced
+ precisely as an alternative to RSA—which
+ are <i>not affected</i> by this attack.
+ </li>
+ </ul>
+ We provide more technical details in the section below.
+</p>
+<p>
+ Though we've never recommended using RSA-1024 and the academic attack is rather
+ expensive, it still makes sense to analyze it to derive what its implications
+ are on how one should configure a GNU Taler exchange, after all forging RSA
+ signatures would enable an attacker to print money and bankrupt Taler
+ exchange operators! What follows is a coarse back-of-the-envelope rough
+ extrapolation of the cost of the attack against the standard GNU Taler
+ configuration.
+</p>
+<h2>Technical Details</h2>
<p>
At a high level, the attack requires two steps: obtaining many signatures, and
then doing an expensive computation using them. At RSA-2048, the recommended