Live data from Hacker News

Factoring may be easier than we think (2016)

math.mit.edu

101–110 of 174 posts

Re: Factoring may be easier than we think (2016)

#101

Imagine what you would do if you discovered how to factor efficiently? Think carefully. You now how the power to decrypt much of the world's banking and internet traffic and spoof certificates. There are forces in this world that would kill you to have this power. Would you publish your findings for everlasting fame? Would you sell it to the NSA for money (remember you can prove your power without releasing your algo…

[deleted]

Re: Factoring may be easier than we think (2016)

#102

Earlier quoted context omitted.

You're going to have to launder a lot of money. What's your strategy there?

Why launder? Plenty of goods and services would accept crypto as payment. No need to launder cryptocurrencies but the wild swings in price will affect your accounting in your business.

presumably this darknet service to decrypt RSA is being used for nefarious purposes. i suppose you could prevent yourself from having access to the stuff people are decrypting and hope some kind of safe-harbor law would protect you.

Re: Factoring may be easier than we think (2016)

#103
post #8

The US federal government once expended 10 percent of the US's electric energy supply in the Manhattan project for getting weapons grade nuclear material. This gives a rough ballpark for the amount of energy they are willing to invest into major strategic advancements. However, if you apply Landauer's principle, current factoring algorithms would require enough energy to boil all oceans on the earth, that's a lot eve…

> This gives a rough ballpark for the amount of energy they are willing to invest into major strategic advancements.

I'd say, rather, that it gives a rough ballpark of how much the government was willing to invest in the 1940s, at the peak of its ability and willingness to take on projects of incredible scope. There was still a fair amount of this for a few decades after that, but not since the 70s. See https://rationalconspiracy.com/2012/06/03/why-doesnt-our-gov... for one person's take on this (though you don't have to go as far as she does, I think, to establish that applying Manhattan Project numbers to anything going on today will result in an overestimate).

Re: Factoring may be easier than we think (2016)

#104
post #51

Earlier quoted context omitted.

The altruistic answers have already been posted, so here's what the devil on my shoulder recommends: I'd start a darknet web service, paid in crypto currency, that decrypts RSA. I'd adjust the price regularly to maximize my profit. The world would go crazy and very rapidly upgrade all software to not use prime factoring based encryption. I'd retire early to some lovely place, and never, ever, tell anyone how I got al…

You're going to have to launder a lot of money. What's your strategy there?

Use a mixer.

Re: Factoring may be easier than we think (2016)

#105
post #14

Imagine what you would do if you discovered how to factor efficiently? Think carefully. You now how the power to decrypt much of the world's banking and internet traffic and spoof certificates. There are forces in this world that would kill you to have this power. Would you publish your findings for everlasting fame? Would you sell it to the NSA for money (remember you can prove your power without releasing your algo…

I once asked this a cryptographer. His response was that he would do the following things (if I remember correctly): * Discuss the result with a few cryptographers he trusts, to check whether he didn't make a mistake and to make sure he's not the only one who knows about it. * Write a paper. Put in all kinds of silly things, because it will get published anyway. * Publish proof of having found the algorithm, together…

Is there any alternative to factoring for asymmetric cryptography? I was under the impression even elliptic curves are based on factoring (though not a cryptographer myself). If that’s the case we would have to live in a world with no asymmetric encryption. That would be interesting.

Re: Factoring may be easier than we think (2016)

#106
post #66

Earlier quoted context omitted.

Why launder? Plenty of goods and services would accept crypto as payment. No need to launder cryptocurrencies but the wild swings in price will affect your accounting in your business.

I'm not very familiar with cryptocurrencies, but wouldn't you be able to also crack crypto wallets? If so, wouldn't the value of crypto go down to 0 thanks to your service?

Bitcoin uses an elliptic curve algorithm secp256k1 for signing. This would be the relevant thing to break to take control of wallets.

Re: Factoring may be easier than we think (2016)

#107
post #14

Earlier quoted context omitted.

I once asked this a cryptographer. His response was that he would do the following things (if I remember correctly): * Discuss the result with a few cryptographers he trusts, to check whether he didn't make a mistake and to make sure he's not the only one who knows about it. * Write a paper. Put in all kinds of silly things, because it will get published anyway. * Publish proof of having found the algorithm, together…

What would happen if you publish publicly? The cat's already out of the bag, they could not possibly want anything more from you, the info is out in the open. Obviously, this isn't ethical but math isn't illegal so there would be no legal consequences. You would be infamous. No, I think this is a danger to you as long as you, and only you know about it. Now, in the case you were to immediately publish this after you…

5) run faster than the NSA/CIA, FSB, DGSE, GCHQ/MI6, etc. Because if any of them finds you they will challenge your opsec with a wrench or with electrical wires strategically placed.

Re: Factoring may be easier than we think (2016)

#108

Imagine what you would do if you discovered how to factor efficiently? Think carefully. You now how the power to decrypt much of the world's banking and internet traffic and spoof certificates. There are forces in this world that would kill you to have this power. Would you publish your findings for everlasting fame? Would you sell it to the NSA for money (remember you can prove your power without releasing your algo…

I would keep it quiet, and only use it occasionally as a "last resort weapon" for breaking DRM and other user-hostile forms of security, like a digital Robin Hood. Its use would have to be very carefully obfuscated so that people would suspect other things first.

...there's probably already sci-fi around that idea, but if not it'd be a great plot.

Re: Factoring may be easier than we think (2016)

#109

Earlier quoted context omitted.

It's basically that BPP captures all realistic polynomial-time computations. The speedup would have to be sufficient to show something like a problem in BQP that isn't in BPP. I don't think anyone has been able to show that unconditionally yet. You'd also need to accept that Quantum computers are realistic, which is why Aaronson's trilemma includes quantum computers being impossible.

This sort of statement is exactly why serious people shouldn't take "quantum complexity theory" seriously. The complexity class BQP is bullshit: there are no quantum computers, the end. Feel free to prove me wrong by building one which does useful calculations. No time limit, until you die, in which case "time's up." Edit add for downvoters: the strong Church Turing thesis is also almost certainly, and very obviously…

Which statement are you saying demonstrates why people shouldn't take quantum complexity theory seriously?

Re: Factoring may be easier than we think (2016)

#110

Imagine what you would do if you discovered how to factor efficiently? Think carefully. You now how the power to decrypt much of the world's banking and internet traffic and spoof certificates. There are forces in this world that would kill you to have this power. Would you publish your findings for everlasting fame? Would you sell it to the NSA for money (remember you can prove your power without releasing your algo…

1. Setup few servers operating in different countries, pay for a few years and set up a timer which will publish this algorithm on few public websites, then destroy all credentials, so it could not be undone.

2. Steal bitcoins from very old wallets with some small amounts. Supposedly those wallets are lost. Steal enough to have enough money to live a good life. Well, if for some reason I would have enough money, skip this step.

3. Break google.com certificate and mail hashes to Google Security team. Ask them to disclose that factorization is broken, so the rest of the world can prepare. Repeat with some other big companies.

4. Disclose algorithm when the world is ready.

Post reply on HN