One problem is that the core-years for RSA-250 were in 2017 Skylake Xeon single core terms.
If you can rent a dedicated 96-core Epyc for $1/hour (cheap dedicated host), the combination of IPC improvements (>2x) and core count make 7,010 "skylake core-years" cost only $175k, not $5M. On-demand cloud servers (which cost more than $1, maybe $5/hour) probably make the GPU cheaper, but it's closer than the author says.
The discussion on the cost of the attack needs an addendum. The lattice sieving part would be free for an an attacker with a big enough botnet or enough cloud computing stolen credentials.
Maybe it could even be practical to run it on browser in parallel to video streaming on a free video site...
I'm confused by this because I was involved in various distributed computing projects from about 1997 to about 2001 (as a person running compute notes for them) and from about 2001 to 2019 (as a person helping to administer a distributed computing related prize), and in the early part of that era we routinely talked about idle computer power as "wasted" because of the idea that the computer might as well be used to compute something rather than sitting idle. This may have been very credible in 1990s devices that consumed a roughly comparable amount of power regardless of what specific computation they were performing, but all modern devices have extremely variable power consumption depending on the load. You can easily feel this as devices have fans turn on or get hot when the CPU is loaded, and in many cases you can easily query the CPU with software to find out how its power consumption or clock rate or other factors get adjusted based on computational load.
This means that the idea that idle compute would have gone to waste is just no longer true on modern devices.
Now there is certainly compute that couldn't be sold to a paying cloud customer because it's too fragmented in some sense, but it still has some amount of energy cost, and, in a data center, corresponding cooling cost attributable to the marginal heat production. How can one actually say that there is literally no marginal cost at all? I just can't imagine a device that literally has the same power draw regardless of load factor!
If it's cloud compute that would be otherwise unused, the business is not paying for the electricity or wear. And they specifically put it in terms of marginal cost - Yeah there'd be an improvement from reselling this idle compute instead, but just using the cycles that would otherwise have been wasted doesn't change the status quo.
If you can rent a dedicated 96-core Epyc for $1/hour (cheap dedicated host), the combination of IPC improvements (>2x) and core count make 7,010 "skylake core-years" cost only $175k, not $5M. On-demand cloud servers (which cost more than $1, maybe $5/hour) probably make the GPU cheaper, but it's closer than the author says.
Normally we'd downweight a follow-up [1] but this is a good article and arguably adds SNI [2] in its own right.
[1] https://hn.algolia.com/?dateRange=all&page=0&prefix=true&que...
[2] https://hn.algolia.com/?dateRange=all&page=0&prefix=false&so...
Maybe it could even be practical to run it on browser in parallel to video streaming on a free video site...
"factorization ran at no marginal cost on spare or fragmented compute that couldn’t be used for other purposes"
Interesting use of stranded compute.
This means that the idea that idle compute would have gone to waste is just no longer true on modern devices.
Now there is certainly compute that couldn't be sold to a paying cloud customer because it's too fragmented in some sense, but it still has some amount of energy cost, and, in a data center, corresponding cooling cost attributable to the marginal heat production. How can one actually say that there is literally no marginal cost at all? I just can't imagine a device that literally has the same power draw regardless of load factor!