4 ms·
That's not necessarily the case in general. If you had an algorithm which, given a billion dollars' worth of specialized lattice reduction ASICs, could break 2
by DanielMcLaury 6y ago
That's not necessarily the case in general. If you had an algorithm which, given a billion dollars' worth of specialized lattice reduction ASICs, could break 2048-bit RSA in a few months' time, then for all practical purposes this would mean that 2048-bit RSA was broken -- there are plenty of state actors who would drop that kind of money in a heartbeat -- but that doesn't mean that some guy who came up with it would be able to do a demo on his laptop.
(Not saying that the above has anything to do with this paper in particular.)
- hn_throwaway_99 6y agoBut still it would be trivial to write a program that could demonstrate this, no? Something that you could show that perhaps broke an unreasonably short RSA key in a shorter time than expected.