Modern & Applied Cryptography Breakers Intermediate
Breaking RSA with Håstad's Broadcast Attack
A low public exponent like e=3 is efficient and, by itself, still safe. Broadcast the same message to three recipients using e=3 with no padding, and the Chinese Remainder Theorem recovers it with no private key at all.