4 ms·
Interesting post, thanks. I find 512-bit RSA keys interesting because they seem to be in occasional use but are within the realms of amateur factoring. From m
by dredge 16y ago
Interesting post, thanks.
I find 512-bit RSA keys interesting because they seem to be in occasional use but are within the realms of amateur factoring.
From my limited experiences of smaller keys (high 400-bit range) I'm actually slightly surprised you didn't get there in 70 days on an 8-way machine. How many relations did you find?
- jgrahamc 16y agoI'd have to pull up the log file to take a look as I've completely forgotten now. IIRC There were plenty of relations and it was pretty far gone through the sieving when we had a power outage and then I had to travel too much and then... life intervened. The oddest part is that the RFCs on DKIM recommend against keys below 1024 bits.
- NateLawson 16y agoThe post cites 1999 stats on cracking 512-bit keys. The recent TI calculator hack is a better data point. http://www.mail-archive.com/cryptography@metzdowd.com/msg10781.html http://www.mail-archive.com/cryptography@metzdowd.com/msg107... Some fun statistics: - The factorization took, in total, about 1745 hours, or a bit less than 73 days, of computation. (I've actually been working on this since early March; I had a couple of false starts and haven't been able to run the software continously.) - My CPU, for reference, is a dual-core Athlon64 at 1900 MHz. - The sieving database was 4.9 gigabytes and contained just over 51 million relations. - During the "filtering" phase, Msieve was using about 2.5 gigabytes of RAM. - The final processing involved finding the null space of a 5.4 million x 5.4 million matrix.