90 comments
I had Claude port CADO-NFS to run on GPUs. Then it orchestrated a fleet to run on scavenged idle capacity. It ran with a max of 2048 GPUs for about of 30 GPU-years over 10 days.
I asked Claude if it had a message for a public: “The credit belongs first to the people who built the number field sieve and CADO-NFS over several decades, and to the teams who set the earlier records. This run used their algorithm and much of their code.”
Also to clarify:
- No new algorithmic factoring improvements.
- It’s still exponential.
- No new threats to deployed keys.Back of the envelope.. 1024 bit keys with recordings of not too old data can probably be found (MS only deprecated them in 2024 even if they planned on it in 2013)
How long would it take for NSA to crack them if they had say the equivalent of a million GPU's? (either GPU's or crypto tuned ASICs)
Something I've often wondered is where the curve between "shit encryption / nation state cracking" crosses.
How much CPU would you need to be Annoyingly Difficult to crack?
I reckon with elliptic curves you could be quite annoying within about a minute on a 1980s-level CPU, to the extent that you could send a fairly ephemeral message quite quickly that would take disproportionately long to crack. Certainly long enough for the thing you have communicated to be no longer worth the effort to know.
You could probably do 256-bit Curve25519 key generation in under ten minutes on an Apple II or Commodore 64, because the 6502's maths is terribly limited, but something like the Tandy Color or Dragon 32 with its 6809 processor (or hey why not the Ensoniq Mirage sampler?) could do that in probably a minute or so because it has a MUL opcode that's quite fast.
I reckon that would keep even a fairly interested nation state chewing away long after your message had been read, understood, and acted upon.
> 1024 bit keys with recordings of not too old data can probably be found
I think GitHub might turn into a scary vector of supply chain attacks in the foreseeable future. There is a five digit number of users still running around with 1024 bit RSA keys.It's actually subexponential: https://en.wikipedia.org/wiki/General_number_field_sieve?wpr...
Devin (their AI agent) ported CADO-NFS to run on GPUs, similarly without any claimed algorithmic factoring improvements, they just let it run for 13 GPU-years. I recommend reading their article since it's much more thorough on details.
I’ll post more details once I get a chance. I wanted to publish as soon as I had the factors because I was beat by 48 hours last time.
Thus, it appears, that ~585 GPU years can factor 1024 bit RSA. 2.2^((1024-896)/34)=19.5, expected growth of resources' usage compared to 896 bits factorization, multiplying it by 30 GPU years for 896 bits gives about 585 GPU-years.
This will cost about $20M with Cognition AI setup.
https://dns.google/resolve?name=pm._domainkey.instagram.com&...
https://vectree.io/c/how-rsa-key-sizes-map-to-real-security-...
Though, it would make more financial sense to mine crypto.
GPUs are power-inefficient for mining most crypto so not necessarily. You may end up paying more in electricity than you are able to mine.
Most crypto mining is on ASICs now.
Also, even if they were paying for electricity, they would lose less money mining crypto than factoring RSA numbers.
That's entirely why they can blow compute on the fun projects like this. If they had to pay extra for the electricity, they wouldn't do it.
There is cost, but the cost is mostly the opportunity cost of not being able to do something else.
Read the full thread on Hacker News →
Related stories
- Forging 1024-bit RSA signatures in nearly SNFS timeeprint.iacr.orgLobsters · 7 points · 6 days ago
- Ars Technica · 0 points · 7 days ago
- Lobsters · 1 points · 6 days ago
- Hacker News · 4 points · 7 days ago
- Bernstein's Factorization Method Helped Factor RSA-240 in 2020leetarxiv.substack.comHacker News · 2 points · 9 days ago
- New RSA attack forges signatures without factoring the keyarstechnica.comHacker News · 3 points · 6 days ago