home *** CD-ROM | disk | FTP | other *** search
- Path: sparky!uunet!gatech!darwin.sura.net!zaphod.mps.ohio-state.edu!pacific.mps.ohio-state.edu!linac!att!ucbvax!virtualnews.nyu.edu!brnstnd
- From: brnstnd@nyu.edu (D. J. Bernstein)
- Newsgroups: sci.crypt
- Subject: Re: RSA-129 contest
- Message-ID: <18112.Aug3004.30.1292@virtualnews.nyu.edu>
- Date: 30 Aug 92 04:30:12 GMT
- References: <1992Aug26.132003.5928@linus.mitre.org> <19122.Aug2700.12.0192@virtualnews.nyu.edu> <1992Aug27.111639.16325@linus.mitre.org>
- Organization: IR
- Lines: 47
-
- In article <1992Aug27.111639.16325@linus.mitre.org> bs@gauss.mitre.org (Robert D. Silverman) writes:
- > :Why are you trying to discourage people from
- > :entering the RSA-129 contest, Bob?
- > Now this last accusation really is obnoxious, because it puts words
- > in my mouth that I have never said.
-
- Bob, you stated that a 6-7 digit improvement in GNFS polynomials in this
- range would result in only a 2x speedup. If this were true, it would put
- a rather small cap on the possible benefits of the RSA-129 contest.
-
- It is not, in fact, true. It is wildly inaccurate: as I pointed out
- before, such an improvement could easily gain an order of magnitude in
- speed. (For instance, p(9) is more than ten times p(10), p being the rho
- function; here N(a,b) is compared to (max AFB)^9.) You had your chance
- to retract the statement, Bob, and you failed.
-
- Someone who believed your misstatement about speedups would obviously be
- discouraged from entering the RSA-129 contest. Bob, what's your
- motivation? Why are you trying to squash interest in GNFS? You're
- achieving the effect of lying to the public, even if you don't mean to
- do so. I don't care whether it's obnoxious of me to point this out---I
- can't sit by and watch you corrupt the views of people who haven't
- learned about GNFS and can only go by what they hear from others.
-
- > All you are doing is gainsaying my data without posting data of your own.
-
- That's right. The bulk of data which I have is part of an article I'm
- writing with Arjen Lenstra on our GNFS implementation. That data, like
- your data, is not sufficient to conclude that GNFS will probably be
- slower than MPQS at 129 digits. Yet you keep stating this conclusion.
-
- > you are confusing the two functions.
-
- My apologies. I mistakenly thought that you were talking about Dickman's
- rho function, which (I can say with some assurance now that I've checked
- my references) a few people attribute to Knuth and Trabb Pardo (because
- Knuth and Trabb Pardo did publish some things about it).
-
- I guess you are referring to the logarithmic sum that Schroeppel
- originally suggested for choosing multiples for the continued fraction
- method. If so, I am astounded at your statement that it would be nice to
- have such a function for the algebraic side of GNFS---everyone knows
- what it is, namely the sum of log p times the (easily computable)
- probability that a coprime pair a,b has N(a,b) divisible by p^d, over
- all p and d.
-
- ---Dan
-