229 points•madars•11 days ago•90 comments•

90 comments

madars11 days ago
More details: https://x.com/sweis/status/2101484464807596264

    I had Claude port CADO-NFS to run on GPUs. Then it orchestrated a fleet to run on scavenged idle capacity. It ran with a max of 2048 GPUs for about of 30 GPU-years over 10 days.
    I asked Claude if it had a message for a public: “The credit belongs first to the people who built the number field sieve and CADO-NFS over several decades, and to the teams who set the earlier records. This run used their algorithm and much of their code.”
    Also to clarify:
    - No new algorithmic factoring improvements. 
    - It’s still exponential.
    - No new threats to deployed keys.
whizzter11 days ago
10 days of 2048 GPU's.

Back of the envelope.. 1024 bit keys with recordings of not too old data can probably be found (MS only deprecated them in 2024 even if they planned on it in 2013)

How long would it take for NSA to crack them if they had say the equivalent of a million GPU's? (either GPU's or crypto tuned ASICs)

walrus0111 days ago
A sufficiently motivated person with a good thermal camera and a cessna 172, entirely within the bounds of the law, could probably make an estimate of the waste heat from this, and then calculate backwards for how much compute power it is.

https://en.wikipedia.org/wiki/Utah_Data_Center

upofadown10 days ago
Hard to judge. The bottleneck is the phase of the algorithm where a really big linear system needs to be solved. That takes a lot of communication between nodes. The breakthrough in using GPUs is that there is good communication between nodes[1]. At the scale of 1024 bit RSA the communication might become a bottleneck again.

[1] https://cognition.com/blog/factoring-rsa-260

ErroneousBosh11 days ago
> How long would it take for NSA to crack them if they had say the equivalent of a million GPU's? (either GPU's or crypto tuned ASICs)

Something I've often wondered is where the curve between "shit encryption / nation state cracking" crosses.

How much CPU would you need to be Annoyingly Difficult to crack?

I reckon with elliptic curves you could be quite annoying within about a minute on a 1980s-level CPU, to the extent that you could send a fairly ephemeral message quite quickly that would take disproportionately long to crack. Certainly long enough for the thing you have communicated to be no longer worth the effort to know.

You could probably do 256-bit Curve25519 key generation in under ten minutes on an Apple II or Commodore 64, because the 6502's maths is terribly limited, but something like the Tandy Color or Dragon 32 with its 6809 processor (or hey why not the Ensoniq Mirage sampler?) could do that in probably a minute or so because it has a MUL opcode that's quite fast.

I reckon that would keep even a fairly interested nation state chewing away long after your message had been read, understood, and acted upon.

gpugreg11 days ago

    > 1024 bit keys with recordings of not too old data can probably be found
I think GitHub might turn into a scary vector of supply chain attacks in the foreseeable future. There is a five digit number of users still running around with 1024 bit RSA keys.
wslh11 days ago
> It’s still exponential

It's actually subexponential: https://en.wikipedia.org/wiki/General_number_field_sieve?wpr...

sweis11 days ago
I misspoke and corrected down thread.
cwillu11 days ago
…but super-polynomial.
bertonvv11 days ago
It seems that Eric Lu at Cognition AI used the exact same strategy on fewer GPUs to factor RSA-260 a couple weeks ago: https://cognition.com/blog/factoring-rsa-260

Devin (their AI agent) ported CADO-NFS to run on GPUs, similarly without any claimed algorithmic factoring improvements, they just let it run for 13 GPU-years. I recommend reading their article since it's much more thorough on details.

sweis10 days ago
Yep, they ran on some newer GPUs so were able to use fewer. Their implementation was faster than mine on RSA-260. For RSA-896, mine improved the performance a bit and selected a good polynomial.

I’ll post more details once I get a chance. I wanted to publish as soon as I had the factors because I was beat by 48 hours last time.

thesz10 days ago
34 bits of key growth resulted in resource usage growth slightly more than 2 (30 GPU-years vs 13.5 GPU-years).

Thus, it appears, that ~585 GPU years can factor 1024 bit RSA. 2.2^((1024-896)/34)=19.5, expected growth of resources' usage compared to 896 bits factorization, multiplying it by 30 GPU years for 896 bits gives about 585 GPU-years.

This will cost about $20M with Cognition AI setup.

weinzierl11 days ago
What does "scavenged idle capacity" mean here?
JoshTriplett11 days ago
The author works at Anthropic, so probably idle capacity in Anthropic's datacenters.
dgacmu11 days ago
If you look at the numbers, he managed about 50% utilization of those 2048 GPUs over 10 days, so he was probably sneaking in factoring work between training runs.
vavkamil11 days ago
Interesting. Instagram still publishes a 768-bit RSA DKIM key, so I guess factoring it is now just a weekend GPU project?

https://dns.google/resolve?name=pm._domainkey.instagram.com&...

functional_dev11 days ago
RSA-768 was already factored in 2009.. cheap now. What surprised me is that RSA keys are much weaker than their size looks. You need 2048 bits to get normal safety, and 768 is far below that.

https://vectree.io/c/how-rsa-key-sizes-map-to-real-security-...

natdempk10 days ago
What's the cost estimate to factor this?
tristanj11 days ago
If you've already paid for and reserved a whole cluster of GPUs, any idle capacity is capacity you've already paid for. Using it is effectively free. So might as well use it to solve fun math puzzles.

Though, it would make more financial sense to mine crypto.

qurren11 days ago
> it would make more financial sense to mine crypto

GPUs are power-inefficient for mining most crypto so not necessarily. You may end up paying more in electricity than you are able to mine.

Most crypto mining is on ASICs now.

aidenn011 days ago
You missed the part where they have already pre-paid for the GPU-hours and they pay the same regardless of he electricity used.

Also, even if they were paying for electricity, they would lose less money mining crypto than factoring RSA numbers.

ehe78qhe11 days ago
Only if you pay a flat rate for electricity and cooling.
tristanj11 days ago
But Anthropic isn't paying for the electricity and cooling. They don't run their own data centers, they rent compute from providers who cover those costs.

That's entirely why they can blow compute on the fun projects like this. If they had to pay extra for the electricity, they wouldn't do it.

odo124211 days ago
Most of the GPU cost is in the GPUs themselves (and in the space and maintenance costs of the building). Electricity is a small fraction, and it's not like datacenters are just going to shut down their servers when they're not in use.

There is cost, but the cost is mostly the opportunity cost of not being able to do something else.

logicallee11 days ago
How much crypto do you think the mentioned 30 GPU years would have produced at current exchange rates? They're not as efficient as ASICs but GPU's can still mine a lot...
monster_truck11 days ago
wouldn't even cover the cost of power and cooling otherwise everyone would still be doin it
charlieyu111 days ago
Except you can do it with CPUs as well for much cheaper.
redox9911 days ago
Quite bearish on Anthropic if they had nothing better to do with 2048 GPUs for 10 days than finding an RSA number with already existing algorithms.
0x10ca1h0st10 days ago
I think you are missing the "idle capacity" information. The GPUs are not running 24/7, there may be minutes of time in a day where there is not an active job running, the author simply located these inactive GPUs during the downtime and utilized it until another job was queued.
redox9910 days ago
Yeah it's a bit ambiguous, but in any case I'd think simply using that idle capacity to generate tokens would be more valuable than finding a basically meaningless number.
muglug11 days ago
1 engineer != Anthropic
hinkley10 days ago
Someone allocated those GPUs.
someguydave11 days ago
kinda bearish for the data center rollouts if the spare compute can be used to solve math puzzles instead of training LLMs

Read the full thread on Hacker News →

Related stories