← Back to context

Comment by tptacek

6 hours ago

That's a weirdly confident prediction. Why do you think 309 isn't going to fall in our lifetimes?

"SHA2 will never be broken in our lifetimes" is something I've heard JP Aumasson say many times, but that's based on the fact that there's no line of sight anywhere to techniques that could break it. But you can't say that about 1024 bit RSA.

Everyone wants to argue crypto when my point was precisely the opposite (to wit: "Two decades after the factoring freakout, RSA is fine, go figure"), but whatever. I'll retract that when they break it. But the pace has been slowing down, not speeding up. Getting from RSA-250 to -260 was six years. That's not going to get us there before I kick it, at least.

If you want to pin me down on something slightly more formal: DRAM density scaling kinda stopped a few years back, systems aren't getting any bigger (much to Sam Altman's public dismay), and there is a superlinear matrix size requirement in factorization techniques that AFAIK no one knows how to fix. We can get the cycles to do it, but not the space.

Probably. Maybe not! But even so, it will remain cheaper to steal my secrets with the proverbial $5 wrench. RSA? It was fine.

honestly I wouldn't be shocked if 2048 bit rsa gets factored in our lifetime. GNFS doesn't have the feel of an optimal algorithm. dropping to L(1/4) would bring 1500 bits into reach, and it seems plausible still that factoring is polynomial.