The forgery attack drops these levels to 2^65, 2^90, and 2^119 for 1024-, 2048-, and 4096-bit keys respectively.
Well that’s terrifying, and all the more reason to get off of RSA signatures and onto anything else, probably EdDSA. Even though the article and paper don’t address the real-world systems which use padding, the algorithmic safety that underpins RSA is under serious scrutiny. It’s hard to see how RSA 4096-bit keys can remain as a first choice, when this type of attack exists and there are credible alternatives, both PQC and not.
The fact of the matter is that for signatures where there isn’t an HNDL problem, we still have the issue of being confident in the signature years after signing. Will an RSA-4096 signed blob be acceptable in 20 years? Do we really think RSA will be above reproach by then? Signers in 2026 might do well to at least have a second signature scheme in place to doubly sign their blobs, and to maybe revalidate then doubly re-sign older blobs previously signed with just their RSA keys, to maintain their provenance for decades to come.


