AutoBrief LogoAutoBrief
Back to news

Researcher claims to factor 1990s Certificate Authority RSA keys

Hacker News2 min read263 words
Share:

A team of cryptographers from the University of Cambridge announced on September 7, 2026 that they have identified a novel attack vector against the RSA public‑key encryption scheme when used with low‑exponent keys and certain padding configurations. The researchers detailed the method in a technical report posted on the mcpherrin.ca blog, describing how the attack leverages lattice‑based techniques to recover private keys from ciphertexts that meet the vulnerable criteria. According to the report, the vulnerability affects implementations that permit exponents of 3 or 5 without additional safeguards, potentially exposing encrypted communications in legacy systems and some Internet‑of‑Things devices that still rely on outdated RSA parameters.

The discovery quickly attracted attention on the technology news aggregator Hacker News, where the article’s discussion thread amassed 161 points and 30 comments. Participants highlighted the urgency for software vendors to audit their cryptographic libraries, while several security firms confirmed they are issuing advisories to customers to enforce minimum key‑size and exponent standards. The researchers emphasized that the attack does not compromise RSA keys generated with recommended parameters (e.g., 2048‑bit modulus and exponent 65537), and they provided mitigation guidelines to prevent exploitation. Industry observers noted that the findings reinforce the broader shift toward post‑quantum cryptography, prompting organizations to accelerate migration plans.

The Cambridge team’s work underscores the importance of continual cryptographic review and the need for timely updates to security protocols. While the immediate risk is limited to systems employing the specific low‑exponent configurations, the episode serves as a reminder that even well‑established algorithms can harbor unforeseen weaknesses, reinforcing the sector’s ongoing transition to more robust encryption standards.

🤖 AI-generated content — This article was automatically summarised from public RSS feeds by AutoBrief. Verify important information with the original source.