Dan Boneh had an interesting paper on this topic a few years back giving some evidence that that breaking RSA might in fact be easier than factoring.However, it defines breaking RSA as being able to DO the private-key operation, not as knowing the private key (because the latter lets

