asciilifeform: i thought in ro cosmography england was an uninteresting backwater. or is that only mircea_popescu
asciilifeform: but there at least they dun pretend to have created the airplane.
asciilifeform: there was a '90s american film where there is a scene, where an airplane lands in africa and in fast motion gets stripped for parts, like elephant carcass by hyenas☟︎
asciilifeform: depressing reading. 'suddenly dud rsa keys, hip!'
asciilifeform: looking for any kind of outliers by any conceivable measure
asciilifeform: reminds me, not long before the beginning of the time of dulap troubles, and the isp winter, asciilifeform was experimenting with statistical tests of the ~moduli~ a la dieharder
asciilifeform doesn't expect to see a pill against this, other than he already obvious engineering margin of using respectable number of bits of entropy for whole thing
asciilifeform: the other thing, diana_coman , is that if enemy knows that you will never use a p or q below limit l -- he can start bruting from l
asciilifeform: diana_coman: generally speaking, anything one could conceivably walk over, is unsafe - i.e. primes smaller than the number of femtoseconds in a millenium, if i had to give a heuristic
asciilifeform: understand, setting the top bit won't help you, i can just as easily say 'but what if the middle 2000 bits in my prime end up zeros!'
asciilifeform: BingoBoingo: default firmware is known-boobytrapped☟︎
asciilifeform: ( it could buy a veeeery small, in a bottle , flotilla... )
asciilifeform: pretty sure i still have a coin i paid 0 for, lel
asciilifeform: ( i could even readily believe that an , e.g., 25x rise in the heathenbux:btc exch rate would make no practical diff to mircea_popescu . but i suspect that i am not the only one here for whom it would make a palpable diff. )
asciilifeform: now i recall having argued this myself, lol
asciilifeform: ( 2048 rather. but you get the idea )
asciilifeform: ( there are still fewer primes than 2^4096bit phase space )
asciilifeform: somewhat counterintuitively, you still get same result ( minus the time sidechannel leak, naturally )
asciilifeform: afaik the only remaining, and most obvious 'loss' is the one implicit in prime number theorem ( where , wat, ~10k possible rng outputs correspond to same prime output )
asciilifeform: iirc she is pumping it straight from fg.
asciilifeform: ( she is using my sanitized gpg bignum. but i did not preserve koch's faux-rng atrocity ; so anything pertaining to entropy, is new )
asciilifeform: afaik diana_coman exhaustively showed the places