Thanks for this answer. The article makes it sound as though even the 4096-bit versions are now more or less trivial to defeat given a bit of money for a capable machine and this new method:
Even for 2048- and 4096-bit keys, the method reduces the security of RSA to unacceptable levels. The National Security Agency, National Institute of Standards and Technology, and European Union Agency for Network and Information Security require that any cryptosystem should provide a level of no less than 128 or more bits, meaning the operations required must exceed 2^128.
The forgery attack drops these levels to 2^65, 2^90, and 2^119 for 1024-, 2048-, and 4096-bit keys respectively. These levels may further drop because Heninger’s team did all the coding by hand and used no AI or GPUs in performing the forgeries. The researcher said these tools will “almost certainly” drop the security levels further.
Just to put a bit of context on those, OpenAI said they used 180,000 GPUs for training their GPT-5 model. As I understand it, each GPU has ~16,000 cores, and each of those cores does a couple billion operations per second. With that cluster, 2^65 operations takes a couple seconds, 2^90 takes many years, and 2^119 is off in “the sun has grown to surround the Earth” territory. The NSA is concerned with protecting their stuff against organizations with hundreds of billions of dollars, and a hundred of years of time to dedicate dozens or hundreds of people to breaking it. “Not good enough” in that context is a very different bar than what most people have to worry about.
You also need to provide them 2^43 unsalted responses, which is more than a casual few.
Thanks for this answer. The article makes it sound as though even the 4096-bit versions are now more or less trivial to defeat given a bit of money for a capable machine and this new method:
Just to put a bit of context on those, OpenAI said they used 180,000 GPUs for training their GPT-5 model. As I understand it, each GPU has ~16,000 cores, and each of those cores does a couple billion operations per second. With that cluster, 2^65 operations takes a couple seconds, 2^90 takes many years, and 2^119 is off in “the sun has grown to surround the Earth” territory. The NSA is concerned with protecting their stuff against organizations with hundreds of billions of dollars, and a hundred of years of time to dedicate dozens or hundreds of people to breaking it. “Not good enough” in that context is a very different bar than what most people have to worry about.
You also need to provide them 2^43 unsalted responses, which is more than a casual few.