One division is enough
On Thursday morning a sequence of 130 digits appeared on X with two words under it: divides RSA-260. Eric Lu, an engineer at Cognition, had cracked the largest member so far of the list of RSA numbers published in 1991. The whole claim can be checked on a calculator: take the known RSA-260 number, divide it by the 130-digit string Lu supplied, and if nothing is left over the job is done. That asymmetry is exactly what makes factoring a foundation for cryptography — cracking is computationally heavy, checking is child's play.[1]
The other face of that asymmetry: a factor proves the result completely and says nothing at all about the method. Lu has offered very few details about how he found the prime. There is no published algorithm, no software, no hardware list and no running time — only a remark that may have been made in jest, about paper and pencil. For an engineer that is a box seen to work and never opened: the result can be accepted, the construction cannot be rebuilt.[1]
The point to read on the cost curve
There is a point of comparison. The last time was 2020, when a team factored RSA-250; the sieving technique they used sifts out non-primes and leaves only primes to test, and the work ran for several months on the power of tens of thousands of computers. Emmanuele Thomé of INRIA, who was in that group, says factoring RSA-260 is expected to be roughly three times as computationally expensive as RSA-250, and calls what Lu did feasible rather than low-hanging fruit.[1]
Thomé's number gives what the work should cost, not what it did cost. Measuring what Lu actually spent needs the method, and because the method has not been published the achievement cannot be set against the sieving run and the tens of thousands of computers that brought down RSA-250. Another account of the same work is available: Lu may have used sieving on ordinary rented machines, in which case the cost of factoring has not moved since 2020. Reading a benchmark requires knowing the conditions the measurement was taken under.[1]
The 2,000-bit gap
On the encryption side the arithmetic is easy. RSA keys in practice use at least about 2,000 binary bits, more than twice the length of RSA-260. Because hardness rises exponentially as the numbers grow, that gap corresponds not to twice the work but to far more. The number Lu cracked is tiny next to the ones used in modern cryptography, and today's RSA schemes take no damage from this result.[1]
One observable signal is left. If Lu or Cognition publishes the technique, the hardware and the running time behind the factoring of RSA-260, the achievement becomes comparable with the sieving run that factored RSA-250; an independent group repeating the same factoring would do the same job. Until that publication arrives, what remains in hand is a leaderboard entry, and no point appears on the cost curve to read. To understand a result is to be able to rebuild it, and for now the only thing that can be rebuilt is the division.[1]