Live data from Hacker News

I've factored the RSA keys of a Certificate Authority from the 90s

mcpherrin.ca

71–80 of 132 posts

Re: I've factored the RSA keys of a Certificate Authority from the 90s

#71
post #38

In the 90s, how long did people expect it would be until consumer computer hardware would be able to do this so quickly?

In Schneider's 1995 book he estimated factoring a 512-bit number would take roughly 30,000 MIPS-years (a one-million-instruction-per-second computer running for one year).

When a research team actually factored RSA-155 in August 1999, it took 8,400 MIPS-years due to efficiencies discovered. It still took 35 CPU-years spread across a cluster of 300 fast SGI/SUN workstations and Pentium II PCs (400-500 MIPS each), crunching in parallel for seven months. https://cs.ccsu.edu/~pelletie/local/risks/cryptography/Facto...

Robert Silverman, a senior research scientist at RSA Laboratories, published an analysis projecting these new hardware requirements against Moore's Law. His expectation was that within 10 years (roughly 2009–2010), common desktop machines would possess the speed and memory necessary to handle a 512-bit factorization entirely on their own. https://cr.yp.to/bib/2000/silverman.pdf

Re: I've factored the RSA keys of a Certificate Authority from the 90s

#73
post #4

Basically 2 days on a consumer GPU to crack a 512 bit cert. The thing is much of the traffic back then did not use ephemeral keys. Most of it wasn't even encrypted at all! But about a decade later, it became normal to encrypt everything. I do wonder which governments around the world are just waiting to crack anonymous political speech by recording and saving for later when decryption can happen.

Even if they were using the total yearly production of tapes, depending on the estimate you choose, that ~100EB is still only something like 1/50th of yearly internet traffic. Much more realistic to assume if it was worth saving in the first place they established a side channel instead.

Re: I've factored the RSA keys of a Certificate Authority from the 90s

#74

Earlier quoted context omitted.

Oh, I have * strong* opinions about the slop machine. But I try to temper them so I don't get buried by the usual "pro AI" mob I will say that my projects have a "leading the pack" anti-AI policy [1] [1] https://wiki.cursedsilicon.net/wiki/AI_Policy

Is the "pro AI" mob in the room with us? The only real mob I ever see is the one taking every chance to try to put AI down and imply its users are somehow deficient.

This condescending psychiatrist meme implying hallucinatory nature of entities described by one's opponent has got to stop.

Re: I've factored the RSA keys of a Certificate Authority from the 90s

#75
I was the product manager with responsibility for root certificates in the Netscape 4.51 browser. It's crazy to see someone factor it 25 years later.

Just to reply to some people in the comments. Yes, we knew export grade encryption was weak - that was the point - that the NSA could decrypt it - and the govt. required us to do it anyway.

FWIW - we had the goal of expanding the list of root authorities in the 4.5x release - and this might have been the first release to monetize the root slots because Netscape was under severe pressure to generate revenue.

(Also - Verisign hated that we were expanding competition and tried to convince us to implement a program that would re-restrict the list to a set of "responsible" companies aka Verisign and one or two others. We declined.)

Re: I've factored the RSA keys of a Certificate Authority from the 90s

#76
post #22

Earlier quoted context omitted.

For what it's worth, this comment was better than the article... When you outsource to the slop machine, you don't have anything interesting to say (usually).

The slop machine gives answers to your questions. It hallucinates so it's recommended to verify what it says. Shit in, shit out. If you have no idea whatsoever and can't use other sources to verify claims, well, get a different job I guess.

Why use the slop machine then, if you already know or precognize the answer?

Re: I've factored the RSA keys of a Certificate Authority from the 90s

#77

> Assuming you’re somehow running Netscape 4.51 with a clock set before E-Certify roots expired on 2003-10-16, you can use these private keys to issue certificates. This describes zero people on the planet… except for this VM I set up. The planet has a lot of people.

Are very many of them time travellers?

Re: I've factored the RSA keys of a Certificate Authority from the 90s

#78
post #4

Basically 2 days on a consumer GPU to crack a 512 bit cert. The thing is much of the traffic back then did not use ephemeral keys. Most of it wasn't even encrypted at all! But about a decade later, it became normal to encrypt everything. I do wonder which governments around the world are just waiting to crack anonymous political speech by recording and saving for later when decryption can happen.

> which governments around the world are just waiting to crack anonymous political speech by recording and saving for later Probably not too many, because anonymous political speech from 10+ years ago isn't that interesting. Punishing people a decade after the fact isn't very effective for anything.

Blackmail/ influencing elections. Find the presidential candidate's post when he was 14 and said something racist or edgy and use that as leverage or kick him out of the race.

Re: I've factored the RSA keys of a Certificate Authority from the 90s

#79

Earlier quoted context omitted.

Let's flip it, then Is the "anti AI mob" in the room with us right now? If not, why did you feel the need to lament it?

This entire comment section is almost entirely people bemoaning AI output, calling AI a "slop machine", and you posted your regressive religious screed against it as if it were something to be proud of, seemingly to the approval of others. nearly every comment section with AI involved is like this, and many comment sections where AI is not involved. It deserves pushback.

People are indeed proud of remaining humans and resisting becoming AI corp appendages that are lost in slop at their own expense. Get over it. Your pushback is exactly as religious.

Re: I've factored the RSA keys of a Certificate Authority from the 90s

#80

I was the product manager with responsibility for root certificates in the Netscape 4.51 browser. It's crazy to see someone factor it 25 years later. Just to reply to some people in the comments. Yes, we knew export grade encryption was weak - that was the point - that the NSA could decrypt it - and the govt. required us to do it anyway. FWIW - we had the goal of expanding the list of root authorities in the 4.5x rel…

Its a shame that Microsoft ate Netscape's lunch so early on. I still use Firefox and have fond memories of Netscape (v7) when growing up.
Post reply on HN