# How bad is it to leak \$k\$ in RSA?

In RSA using a small public exponent $$e$$ such as $$65537$$, how bad is it if the value $$k$$ leaks? $$k$$ as in the following equations:

$$ed – 1 = k phi(n)$$

or

$$ed – 1 = k cdot mathrm{lcm}(p-1,q-1)$$

Intuitively, this would only reduce the complexity of the breaking the system by $$65535$$ times, nowhere near enough to matter, though I assume that GNFS would not be improved by knowing $$k$$.

