taler-www

Main taler.net website
Log | Files | Refs | Submodules | README | LICENSE

commit 1cf05d9f11d4f66ca904424700d933c84cad9898
parent e02f0bfdc398c99a24fe83046beb6b726b961dc7
Author: Özgür Kesim <oec@codeblau.de>
Date:   Sun, 27 Sep 2026 14:52:19 +0200

[2026-12] more clear exposition how Taler is affected by the attacks against RSA-1024

Diffstat:
Mtemplate/news/2026-12.html.j2 | 55++++++++++++++++++++++++++++++++++++++++++-------------
1 file changed, 42 insertions(+), 13 deletions(-)

diff --git a/template/news/2026-12.html.j2 b/template/news/2026-12.html.j2 @@ -1,21 +1,50 @@ {% extends "common/news.j2" %} {% block body_content %} -<h1>2026-09-27: {{ _("Forging 1024-bit RSA signatures in nearly SNFS time") }}</h1> +<h1> +Successful attacks against 1024-bit RSA signatures</h1> <p> - Laura Shea, Miro Haller, Adam Suhl, Nadia Heninger, and Emmanuel Thomé published - a <a href="https://eprint.iacr.org/2026/2131">report</a> on implementing and - successfully executing a not so well-known attack to forge RSA-1024 signatures - by Joux, Naccache, and Thomé from 2007. The attack applies in principle to - the blind signatures used by GNU Taler and as far as we know is the most - efficient forgery attack on RSA signatures today. So we've never recommended - using RSA-1024 and the academic attack is rather expensive, it still makes sense to - analyze it to derive what its implications are on how one should configure - a GNU Taler exchange, after all forging RSA signatures would enable an - attacker to print money and bankrupt Taler exchange operators! - What follows is a coarse back-of-the-envelope rough extrapolation of the cost - of the attack against the standard GNU Taler configuration. + Laura Shea, Miro Haller, Adam Suhl, Nadia Heninger, and Emmanuel Thomé + published a report <a href="https://eprint.iacr.org/2026/2131"> + <i>"{{ _("Forging 1024-bit RSA signatures in nearly SNFS time") }}"</i></a> + on implementing and successfully executing a not so well-known attack to + forge RSA-1024 signatures by Joux, Naccache, and Thomé from 2007. The attack + applies in principle to the blind signatures used by GNU Taler and as far as + we know is the most efficient forgery attack on RSA signatures today. </p> +<h2>Effects on Taler</h2> +<p> + Any real and recommended deployment of GNU Taler + is not at risk from this attack, + due to the following security measures in GNU Taler: + <ul> + <li><b>Secure defaults:</b> + Taler's default minimal security level is RSA-2048, + which makes the attack <i>economically</i> infeasible in practice. + </li> + <li><b>Key rotation:</b> + Taler supports key rotation of demonination keys, + with a default of once per week, + which makes the attack <i>technically</i> infeasible in practice. + </li> + <li><b>Alternative to RSA available:</b> + Taler supports blind signatures of type Clause-Schnorr&mdash;introduced + precisely as an alternative to RSA&mdash;which + are <i>not affected</i> by this attack. + </li> + </ul> + We provide more technical details in the section below. +</p> +<p> + Though we've never recommended using RSA-1024 and the academic attack is rather + expensive, it still makes sense to analyze it to derive what its implications + are on how one should configure a GNU Taler exchange, after all forging RSA + signatures would enable an attacker to print money and bankrupt Taler + exchange operators! What follows is a coarse back-of-the-envelope rough + extrapolation of the cost of the attack against the standard GNU Taler + configuration. +</p> +<h2>Technical Details</h2> <p> At a high level, the attack requires two steps: obtaining many signatures, and then doing an expensive computation using them. At RSA-2048, the recommended