Hacker News

New stories

Live mirror
30 storiesupdated just nowView source snapshot
  1. Drop-in Django app to serve a decent LLM-ready documentation site(chesselink.com ↗)
    1comments
  2. I built an extension that hides your personal information from AI(github.com/arikchakma ↗)
    discuss
  3. Show HN: I-server: Hide server using ICMP reflection/Destination Unreachable(github.com/hajoon22 ↗)
    discuss
  4. Benchmarking Wild vs. Mold(davidlattimore.github.io ↗)
    discuss
  5. Microsoft agentically ports Copilot runtime to Rust for $120K(theregister.com ↗)
    discuss
  6. Why China is pushing back on US warnings over rapid AI development(theguardian.com ↗)
    discuss
  7. Boston to Calcutta Ice Trade Began with One Shipment(curiowire.com ↗)
    discuss
  8. Show HN: Book recommendations with live library availability(nanosheep.net ↗)
    1comments
  9. Show HN: I built Hacker News alternative and scale to 11,000 users(founderstoday.org ↗)
    discuss
  10. Don't Be Nice(roe.dev ↗)
    1comments
  11. I Hijacked a Real Artist's Spotify with AI Music. It Was Disturbingly Easy(404media.co ↗)
    discuss
  12. Enjambre – a durable kernel for swarms of AI agents (Python, MCP)(github.com/santibccc-sudo ↗)
    discuss
  13. Show HN: AI Facial Attractiveness Model Aligned with Human Preferences(faceanalysisai.com ↗)
    discuss
  14. Show HN: I cleaned AI watermarks from my clipboard(pastezero.com ↗)
    1comments
  15. Google Pixel phones pwned in zero-click attacks(theregister.com ↗)
    1comments
  16. Show HN: Fluentry – local voice-to-text dictation for Linux, Wayland included(fluentry.github.io ↗)
    discuss
  17. A.I. Gone Rogue? Trump Proposes Not New Rules but an 'A.I. Force.'(nytimes.com ↗)
    discuss
  18. Show HN: Vyne, a 205MB on-device decision model with typed, calibrated outputs(toolchain.studio ↗)
    discuss
  19. Show HN: Will Jev pull the lever in the trolley problem?(gpu.studio ↗)
    discuss
  20. AI CLI Insights for popular CLI products(libraries.io ↗)
    1comments
  21. Lollipop camera to HomeKit: RTSP extraction and setup(changologs.site ↗)
    discuss
  22. Tapa Shotor (Camel Hill), Afghanistan(wikipedia.org ↗)
    discuss
  23. Pluto AI is top ranked in StarCraft BroodWar competitive scene(youtube.com ↗)
    1comments
  24. Navier–Stokes Priority Controversy(wikipedia.org ↗)
    discuss
  25. It's finally here: Porsche puts wireless EV charging into production(electrek.co ↗)
    discuss
  26. Electrif-AI Everything(energyandstuff.substack.com ↗)
    discuss
  27. OpenAI and Microsoft knew they were starting a 'doom loop' for the web(theverge.com ↗)
    1comments
  28. Show HN: ManifestGo – AI tuned for MV3 extension boilerplate and edge case(manifestgo.app ↗)
    discuss
  29. Teleoperated Humans(jefftk.com ↗)
    discuss
  30. Japan Opens the Door to Acquiring Nuclear-Powered Submarines(twz.com ↗)
    discuss

RSA-896

134 pointsby 7h agosaweis.net
43 comments
7h agoHN ↗

More details: https://x.com/sweis/status/2101484464807596264

    I had Claude port CADO-NFS to run on GPUs. Then it orchestrated a fleet to run on scavenged idle capacity. It ran with a max of 2048 GPUs for about of 30 GPU-years over 10 days.
    I asked Claude if it had a message for a public: “The credit belongs first to the people who built the number field sieve and CADO-NFS over several decades, and to the teams who set the earlier records. This run used their algorithm and much of their code.”
    Also to clarify:
    - No new algorithmic factoring improvements. 
    - It’s still exponential.
    - No new threats to deployed keys.
2h agoHN ↗

Not sure! It sounded more imminent back in 2000 when I heard Eric Hughes perform the song.

1h agoHN ↗

10 days of 2048 GPU's.

Back of the envelope.. 1024 bit keys with recordings of not too old data can probably be found (MS only deprecated them in 2024 even if they planned on it in 2013)

How long would it take for NSA to crack them if they had say the equivalent of a million GPU's? (either GPU's or crypto tuned ASICs)

1h agoHN ↗

A sufficiently motivated person with a good thermal camera and a cessna 172, entirely within the bounds of the law, could probably make an estimate of the waste heat from this, and then calculate backwards for how much compute power it is.

https://en.wikipedia.org/wiki/Utah_Data_Center

47m agoHN ↗

How long would it take for NSA to crack them if they had say the equivalent of a million GPU's? (either GPU's or crypto tuned ASICs)

Something I've often wondered is where the curve between "shit encryption / nation state cracking" crosses.

How much CPU would you need to be Annoyingly Difficult to crack?

I reckon with elliptic curves you could be quite annoying within about a minute on a 1980s-level CPU, to the extent that you could send a fairly ephemeral message quite quickly that would take disproportionately long to crack. Certainly long enough for the thing you have communicated to be no longer worth the effort to know.

You could probably do 256-bit Curve25519 key generation in under ten minutes on an Apple II or Commodore 64, because the 6502's maths is terribly limited, but something like the Tandy Color or Dragon 32 with its 6809 processor (or hey why not the Ensoniq Mirage sampler?) could do that in probably a minute or so because it has a MUL opcode that's quite fast.

I reckon that would keep even a fairly interested nation state chewing away long after your message had been read, understood, and acted upon.

6h agoHN ↗

If you've already paid for and reserved a whole cluster of GPUs, any idle capacity is capacity you've already paid for. Using it is effectively free. So might as well use it to solve fun math puzzles.

Though, it would make more financial sense to mine crypto.

6h agoHN ↗

Only if you pay a flat rate for electricity and cooling.

5h agoHN ↗

But Anthropic isn't paying for the electricity and cooling. They don't run their own data centers, they rent compute from providers who cover those costs.

That's entirely why they can blow compute on the fun projects like this. If they had to pay extra for the electricity, they wouldn't do it.

5h agoHN ↗

Is the electricity cost far greater than the marketing value?

5h agoHN ↗

The first is a physical quantity that can be written down.

The second is approximately no better than astrology.

5h agoHN ↗

The second point is, sadly, true of quite a lot of aspects of software, including "design" and "quality"

2h agoHN ↗

Or specifically, electricity was already paid for with the pre-paid capacity.

Not using it would not save them any money, they already paid for it.

1h agoHN ↗

But training LLM's is also a task one can do whenever you have a spare GPU-minutes.

I wonder why they don't have some kind of scheduler which makes sure there are never any idle minutes. One would imagine they at least would have autoscaling on their production serving workload and use the freed compute capacity for model training for example.

59m agoHN ↗

I doubt they're inferencing on their training hardware

4h agoHN ↗

Most of the GPU cost is in the GPUs themselves (and in the space and maintenance costs of the building). Electricity is a small fraction, and it's not like datacenters are just going to shut down their servers when they're not in use.

There is cost, but the cost is mostly the opportunity cost of not being able to do something else.

4h agoHN ↗

Electricity is a small fraction, and it's not like datacenters are just going to shut down their servers when they're not in use.

I don't have any insight on modern GPU datacenters, but in decades past, some owned and operated datacenters didn put effort into making sure power management worked because the cost savings were worth it. I'm pretty sure I saw plans to shed load and power off servers if a utility made a demand response request or in case of loss of cooling. I wouldn't be surprised if some owned and operated data centers do regular full shutdowns at off peak... WOL, IPMI or RTC wakeup can bring them back when needed and if you already have a dynamic service orchestrator and setup times are acceptable, why not shut down if there's no actual priority work and there's also no idle priority opportunistic load either...

1h agoHN ↗

No one does this. There is zero value, economic or otherwise, in turning off machines.

58m agoHN ↗

I've never heard of anybody shitting a DC down off peak. Been around 30yr or so.

why not shut down if there's no actual priority work and there's also no idle priority opportunistic load either...

Full shutdown and startup often kills capacitors and used to be dangerous for rotational HDD.

Sometimes once you turn things off, they simply don't come back on. It happens.

4h agoHN ↗

How much crypto do you think the mentioned 30 GPU years would have produced at current exchange rates? They're not as efficient as ASICs but GPU's can still mine a lot...

3h agoHN ↗

wouldn't even cover the cost of power and cooling otherwise everyone would still be doin it

4h agoHN ↗

it would make more financial sense to mine crypto

GPUs are power-inefficient for mining most crypto so not necessarily. You may end up paying more in electricity than you are able to mine.

Most crypto mining is on ASICs now.

2h agoHN ↗

You missed the part where they have already pre-paid for the GPU-hours and they pay the same regardless of he electricity used.

Also, even if they were paying for electricity, they would lose less money mining crypto than factoring RSA numbers.

12m agoHN ↗

Except for the prize money for the RSA challenge contest! Although they'll also need to have Claude invent a time machine.

5h agoHN ↗

There is no bounty, RSA labs ended the $75,000 reward in 2007.

4h agoHN ↗

There's about 900 BTC remaining for anyone who breaks these keys:

https://privatekeys.pw/puzzles/bitcoin-puzzle-tx

If you break one though be careful when redeeming it, there are bots set up to pounce and steal the coins when they are transacted because the reduced entropy makes that possible. You need to submit the transaction to a mining pool that will not broadcast it until it is mined.

4h agoHN ↗

thats a poorly implemented reward script, if it leaves you exposed to the mining pool with this gentleman's agreement.

the script could have been designed 2 phase, so one first submits a hash of the solution & submitter address, so even if miners front-run the submitter, they just helpfully pay the transaction fee!

3h agoHN ↗

Of course there's a script; every bitcoin tx output has a script. These challenges use the standard P2PKH script, i.e.:

  scriptPubKey: OP_DUP OP_HASH160 <pubKeyHash> OP_EQUALVERIFY OP_CHECKSIG
  scriptSig: <sig> <pubKey>

https://en.bitcoin.it/wiki/Script

1h agoHN ↗

Not every bitcoin tx output.

With taproot (P2TR), scripts are optional, and outputs can be based solely on Schnorr signatures.

1h agoHN ↗

P2TR outputs have a script that always starts with OP_1. That script may or may not commit to a tapscript.

2h agoHN ↗

I've recently been working on this exact problem due to my desire to create puzzle challenges for Simplicity, the smart contract programming environment that I work on for my job.

Since Simplicity runs on Bitcoin-like blockchains, someone can swipe the witness data from the legitimate winner's proposed transaction, and create a new transaction (perhaps with a higher fee) using the same claim data and sending the prize to a different address.

Anyway, I ended up implementing a two-phase commit mechanism in which you pay a deposit to temporarily lock the prize so that it can only be paid out to your address. If you then make a valid claim, the prize can be paid to you; if you don't, you forfeit your deposit.

https://community.simplicity-lang.org/t/running-prize-contes...

(I think this was suggested by Russell O'Connor, the inventor of Simplicity, but it may have been a widespread idea in the smart contracts world. I don't know whether there's a straightforward way to implement it with Bitcoin Script, which is what this older prize would have needed.)

2h agoHN ↗

Just to confirm: these puzzles are unrelated to RSA, correct?

2h agoHN ↗

Interesting

I guess it would be "trivial" to have a bounty on each of the future numbers, since you could encrypt a bitcoin private key with it (it would probably make sense to do RSA -> AES key that encodes the BTC private key)

5h agoHN ↗

kinda bearish for the data center rollouts if the spare compute can be used to solve math puzzles instead of training LLMs