3 ms·
It's not so clear. Here, as long as you can afford a near-optimal SHA256 processor, more computing power doesn't help. In the "successive squaring" method (se
by stromgo 12y ago
It's not so clear.
Here, as long as you can afford a near-optimal SHA256 processor, more computing power doesn't help.
In the "successive squaring" method (see the essay posted by gwern), as long as you can afford a near-optimal modular multiplier, more computing power doesn't help.
In both approaches there is a constant cost of the near-optimal hardware, and a confidence level that the hardware is actually near-optimal. In SHA256 the cost is probably lower and the confidence level probably higher, but the difference is quantitative, and not qualitative.