Daily Shaarli
September 29, 2026
Subnet routers
Use subnet routers to give devices outside your local network access to services within specific subnets. Extend your private network with Tailscale.
ArsTechnica is reporting on a “new” attack against RSA, one that bypasses factoring.
First, this attack isn’t new. The original research is from 2007. What is new is the implementation.
Second, it is a forgery attack. It allows an attacker to forge digital signatures. It does not recover the private key from the public key.
Third, the attack only works against pure signatures. That is, signatures without any formatting or padding. This is not generally how we use RSA in practice.
Fourth, speed is all relative. This is not a polynomial-time algorithm; it’s a subexponential-time algorithm. But it is somewhat faster than factoring. The authors were able to forge messages for 1024-bit RSA with 1380 CPU core-years (over five real-world months).
The authors have a webpage that explains the context much better than the article. And here’s the paper.
You can get started for FREE with a 10GB vault. I think that’s really cool, because it’s enough to actually give it a try and use it productively. It’s not time-limited, so you can set up a vault, stream some backups to it, and let it keep working to really test the service.
So I decided to do just that.
I have a small box I use for VPN purposes on DigitalOcean. It’s a 512MB “droplet” (ick – it’s a VPS people). I already back it up to my home lab, but it’s a good candidate for a Restic-based backup.
In general, when I backup, I capture the following:
- Essential file and filesystems, using a “default include” model. I exclude a bunch of directories such as /dev, but by default I include everything.
- I also include “status” dumps, such as dpkg -l, ps -ef, df -h, and other info.
- Finally I do database dumps.
In the case of my VPN server, the things I care about are:
- /etc, where all the OpenVPN config lives
- because I use @Nyr’s Road Warrior script and I put the .ovpn file in /root, I should back that up, too.
- My own backups put data in /backup (dpkg -l output, etc.) so I’ll back that up.