I don't think you can impose an obligation on academic authors to assume that dangerously uninformed people will glom on to keywords like 'RSA', not understand any of the content, and somehow this is the author's burden.
Yes, it creates bullshit for experts to deal with. Unfortunately dealing with bullshit is part of the job. The amount of AI hacking doomerism and naive super optimism I have to deal with is revolting, but grounding the paranoia and boosterism is part of the job.
The people I take issue with are the ones who claim expertise, and then say "This new paper says 1024 but RSA is broken, we must move to PQC immediately!" They are so good at blowing their own trumpet they get appointed to boards and are anointed as experts in regulators, and you can't expose them without experiencing institutional anger.
The same argument can be made for justifying shouting "fire" in a crowded theatre: "It was a war movie, they were taking their time shooting the other guys, I was just encouraging them, there's no obligation on me to assume that dangerously uninformed people will glom on to keywords like 'fire!' and respond to it". Courts have repeatedly ruled that anyone doing that should know better. In this case the actual result is "We present an improvement of an attack by Joux, Naccache, and Thome. While not applicable to the use of RSA today, it presents an interesting new avenue of research for signature forgery". There have been hundreds of papers presented at crypto conferences like this, "here's a neat new attack, theoretical only, but isn't it cool?". They did find one thing that was vulnerable, via direct PKCS #11 API access to an HSM where the vendor forgot to lock down the API properly, but then again if you've got PKCS #11 access there are dozens of ways to pull keys out of an HSM when the vendor doesn't bother locking down their API that don't involve this, and they take a few seconds or minutes, not months. In this case it's the old Luna HSM which has a pile of these vulns, including Mike Bond's work from more than 20 years ago and non-public stuff even before then. This is why no-one allows outside API access to an HSM, once you've got that it's game over.
Instead, the way this one has been presented leads to things like https://it.slashdot.org/story/26/09/24/1652228/theres-a-new-..., "a new way to break RSA encryption". I don't think this was just a case of "oops, we phrased that badly" because an IACR ePrint posting, of which there have been over 2,000 so far this year, doesn't get mainstream IT media coverage unless you've gone out of your way to attract it. Because of this I now have a missed phonecall from someone senior at 3:30am and three followup voicemails (luckily I keep my phone on silent overnight), all from someone who doesn't realise we're in a different time zone, I'll let you guess which country they're from. And I won't be the only one, there'll be a pile of security people in other organisations out there who have had their weekend and/or week messed up by this.
Yes, it creates bullshit for experts to deal with. Unfortunately dealing with bullshit is part of the job. The amount of AI hacking doomerism and naive super optimism I have to deal with is revolting, but grounding the paranoia and boosterism is part of the job.
The people I take issue with are the ones who claim expertise, and then say "This new paper says 1024 but RSA is broken, we must move to PQC immediately!" They are so good at blowing their own trumpet they get appointed to boards and are anointed as experts in regulators, and you can't expose them without experiencing institutional anger.