PaulSpoerry.com

You found me… insights on technology, philosophy, Windows, hacking and more.
  • Home
  • Archive
  • Contact
  • Categories
  • Search
  • About

Researchers: 307-digit key crack endangers 1024-bit RSA

PaulSpoerry | May 24, 2007

A 307-digit encryption key has been broken down into primes, and 1024-bit RSA keys are next, according to encryption researchers. Researchers from the University of Lausanne, the University of Bonn, and NTT DoCoMo have broken a new record in discovering the prime factors of a “special” 307-digit number this month, which took 11 months and roughly 100 years of computer time. The number was cracked using the special number field sieve method developed by cryptology professor Arjen Lenstra in the 1980s.

The 307-digit number itself was not an RSA key—the number was 21039-1, and RSA keys are typically generated by multiplying together two very large prime numbers, each at around 150 digits apiece. But the project shows that given enough time and computer power, the 1024-bit encryption keys used on many e-commerce sites could also be cracked in the not-so-distant future.

“Last time, it took nine years for us to generalize from a special to a nonspecial, hard-to-factor number,” Lenstra said in a statement, referring to a 155-digit number that his team had broken previously. More recently, a 200-digit non-special number was factored in 18 months and roughly 50 years of computer time. This 307-digit crack took even less (human) time, which Lenstra credits to more powerful computers and improved code. “I will not make predictions [about the future of 1024-bit encryption], but let us just say that it might be a good idea to stay tuned.”

Why does anyone care? While your average Joe or Jane on the street will not be able to crack a 1024-bit RSA key anytime soon, experienced attackers might not have such a hard time. Getting the computing power to crack a 1024-bit key could be as easy as employing a decent-sized botnet or two.

When asked whether 1024-bit RSA keys are dead, Lenstra said: “The answer to that question is an unqualified yes.” Hopefully, my bank is paying attention to these developments.

Original Article at Ars.

Post to Twitter Post to Delicious Delicious Post to Digg Digg This Post Post to Ping.fm Ping This Post Post to Reddit Reddit Post to StumbleUpon Stumble This Post

Related posts:

  1. EvilMaid versus Full Disk Encryption (TrueCrypt & PGP)

Categories
Privacy, Tech
Tags
average joe, bit key, botnet, computer power, computer time, computing power, digit number, encryption key, human time, lenstra, ntt docomo, number field sieve, powerful computers, prime factors, prime numbers, primes, rsa key, rsa keys, university of bonn, university of lausanne
Comments rss
Comments rss
Trackback
Trackback

« The Simpsons – Fox News and the Liberal Media Jordin Sparks wins, Blake Lewis loses but beatboxes like a champ with Doug E Fresh (video) »

Leave a Reply

Click here to cancel reply.

You must be logged in to post a comment.

Recent Posts

  • FCC releases Internet speed test tool
  • Microsoft shows games on Mobile, PC, and Xbox
  • Google Voice Explained
  • Windows Mobile 7 to be announced, 6.x to become free
  • Microsoft finally patches 17-year-old bug

Popular Posts

  • µTorrent 1.8.3 Final (uTorrent 1.8.3)
  • Google Chrome’s JavaScript Engine Is CRAZY FAST
  • Google Chrome’s JavaScript Engine Is CRAZY FAST
  • 20 Classic Hip Hop Album Covers Redone With Legos
  • Windows 7 Benchmarks – XP vs Vista vs 7

Recommended Hosting

rss Comments rss valid xhtml 1.1 design by jide powered by Wordpress get firefox