6 comments

  • nk_kolja1 day ago
    Impressive. I wonder the methodology. Algorithmic improvements? More probably just an implementational optimisation. Last RSA record was due to special q sieving methods if I recall well, some 3k core hours. I hope there’s a theoretical improvement behind the result.
    • nk_kolja16 hours ago
      So RSA 260 is about 2-3 times harder than RSA 250, which was solved in 2700 core hours in 2020, so it’s probably no algorithmic improvements, just a tweak here and there plus faster hardware.
      • alexfoo40 minutes ago
        2700 core years
      • mswphd1 hour ago
        faster hardware could also mean gpu/asic/etc.
  • dclavijo1 day ago
    What was the methodology,software, hardware, cpu cores, time taken?
  • samyok1 day ago
    anddd it&#x27;s already on wikipedia <a href="https:&#x2F;&#x2F;en.wikipedia.org&#x2F;wiki&#x2F;RSA_numbers#RSA-260" rel="nofollow">https:&#x2F;&#x2F;en.wikipedia.org&#x2F;wiki&#x2F;RSA_numbers#RSA-260</a>
  • madars1 day ago
    &quot;4397328654844826923795068102505872571721883526553349659561256924505973939597593482272505698004801207988043088656411102133523080581 divides RSA-260&quot;<p>Background: <a href="https:&#x2F;&#x2F;en.wikipedia.org&#x2F;wiki&#x2F;RSA_Factoring_Challenge" rel="nofollow">https:&#x2F;&#x2F;en.wikipedia.org&#x2F;wiki&#x2F;RSA_Factoring_Challenge</a>
  • drfuchs55 minutes ago
    Can I decode my DVD collection now?
    • layer844 minutes ago
      DVD encryption doesn’t use RSA; and yes, you could since late 1999 already.
  • ajross1 hour ago
    It&#x27;s sort of fun to remember the genuine worry in the community around RSA and the (really, really shocking at the time!) progress in factorization leading up to GNFS techniques.<p>Like, it really looked like everything was going to fall apart. We all rushed to 1024 bit keys, and then to 2048 bit after what felt like a few months. And... maybe even that wouldn&#x27;t be enough?<p>And actual history ended up being the boring version: it was absolutely enough, factorization is seemingly settled math at this point, no new techniques have been discovered.<p>At the end of the day RSA was just fine and no one really needed to bother with ECC and all of its confusing tutorials.<p>And the ~23 year old 1024 bit key holding my GnuPG box closed is still just fine, cryptographically. (Though the chances of getting hit with a keylogger or other side channel attack over that period are nontrivially high and I suppose I really should rotate it or something).
    • stouset29 minutes ago
      RSA might be fine mathematically but as a production cryptosystem it’s an unmitigated disaster by modern standards.<p>Compared to elliptic curves, it is comically easy to build an RSA implementation which is catastrophically broken. Both the number of and subtlety of footguns in RSA are extreme.<p>Even ignoring that, ECC is far more efficient (in part thanks to smaller key sizes and being able to be done with fixed-width arithmetic rather than needing bignums) and far better suited for embedded devices. Migration has been an enormous win even <i>if</i> you think the security of RSA is fine.
    • mikestorrent23 minutes ago
      You can just send the gnupg box and keys to me, I will hold them securely for you so you don&#x27;t have to worry about it
    • mswphd27 minutes ago
      the researchers from the RSA-250 record have publicly claimed that factoring 1024-bit RSA keys is within reach of nation states. Your 1024 bit key is only &quot;fine&quot; because you are a small fry, not because cryptographers think it cannot be attacked. This would be true if you used a (non-standard) RSA-768 parameterization as well, which is easier than what we are talking about on this post.<p>It&#x27;s also worth mentioning the main concern for RSA is not GNFS, but something stronger. SOTA RSA attacks (such as GNFS) use &quot;index calculus&quot;. You can also use index calculus to attack finite field diffie hellman. In the 2010&#x27;s, there was remarkable progress in index calculus attacks against finite field DH in the small characteristic case. For example, the current record for binary characteristic finite field DH is ~30k bits (and this is by an academic --- a nation state could definitely do more).<p>It is not known that similar progress is possible in other cases (such as for RSA). But it&#x27;s very much possible that factoring is much easier than expected. Simultaneously I wouldn&#x27;t personally bet money on it, and if that breakthrough happened, there were sufficient warning signs that I would feel justified in saying &quot;told you so&quot; to people trusting RSA.
    • layer841 minutes ago
      ECC does have the benefit of smaller keys, but yes, RSA seems fine security-wise for the foreseeable future.