6 ms·
Basically 2 days on a consumer GPU to crack a 512 bit cert. The thing is much of the traffic back then did not use ephemeral keys. Most of it wasn't even encryp
by goalieca 9d ago
Basically 2 days on a consumer GPU to crack a 512 bit cert. The thing is much of the traffic back then did not use ephemeral keys. Most of it wasn't even encrypted at all! But about a decade later, it became normal to encrypt everything. I do wonder which governments around the world are just waiting to crack anonymous political speech by recording and saving for later when decryption can happen.
- Neywiny 9d agoCPU?
- akoboldfrying 9d agoThe linked CADO-NFS Inria page makes no mention of GPUs, and nor does its downloads page, which makes me think that TFA's factoring was done purely on CPUs. If so, there could still be considerable speedup on the table! The CADO-NFS page gives some benchmark results for 16 threads, suggesting the algorithm parallelises at least somewhat well.
- mcpherrinm 9d agoI didn't use any GPUs, but Steve Weis (who factored the final key at the bottom of the post) did. He's posted about that factoring setup over on https://x.com/sweis/status/2095570645505700165 https://x.com/sweis/status/2095570645505700165
- ThePowerOfFuet 9d agoMuskless link: https://xcancel.com/sweis/status/2095570645505700165 https://xcancel.com/sweis/status/2095570645505700165
- adzm 9d agoIt's possible symmetric encryption may never really be defeated by anything other than brute force. The exchange of the ephemeral key really is the important part, as you mention. Thankfully looks like we are getting closer to full adoption of post quantum TLS... but that doesn't help recorded communications before very recently. Scary thought. Looks like 70% of cloudflare requests are using post-quantum TLS! https://radar.cloudflare.com/post-quantum https://radar.cloudflare.com/post-quantum
- miki123211 8d agoThis makes me wonder why we aren't using pre-shared keys as one extra layer of defense. The idea would be to use an existing connection (established via normal TLS) to agree upon and exchange a pre-shared key. For subsequent connections, that key would be incorporated as one extra input to the key derivation function, and a new key would be derived. This would make TLS more secure against adversaries who can break asymmetric encryption (now or later) and monitor some of your communications, but who do not have access to all of your communications. If you managed to get on an unmonitored network even once (foreign hotel WiFi, coffee shop without a wiretap), and securely establish a PSK there, all future interactions would be inaccessible to an adversary who can't break symmetric crypto.
- tgsovlerkhgsel 9d ago> which governments around the world are just waiting to crack anonymous political speech by recording and saving for later Probably not too many, because anonymous political speech from 10+ years ago isn't that interesting. Punishing people a decade after the fact isn't very effective for anything.
- icefo 9d agoActivists 10 years ago are probably still linked to interesting people the government wants to survey though, even if they are maybe less active now
- utopiah 9d agoActivists typically aren't secretive about their actions, on the contrary they tend to be as public as they can safely be. The setup though might be, if it's to prepare an event that might be crushed down before it even take place, but then even a day later, not even a decade, to decipher would be too late and thus pointless.
- oldgradstudent 9d ago> Punishing people a decade after the fact isn't very effective for anything. It sends a very clear message: even if it takes a decade, we will find you and punish you.
- p-e-w 9d agoThat’s not a message activists tend to care about though. In places where speech is dangerous enough for this to matter, there are usually far more immediate threats.
- suddenlybananas 8d agoIt could potentially have blackmail material.
- gosub100 8d agoBlackmail/ influencing elections. Find the presidential candidate's post when he was 14 and said something racist or edgy and use that as leverage or kick him out of the race.
- monster_truck 8d agoEven if they were using the total yearly production of tapes, depending on the estimate you choose, that ~100EB is still only something like 1/50th of yearly internet traffic. Much more realistic to assume if it was worth saving in the first place they established a side channel instead.