Has anyone worked out an estimate for when prime factorization of 4096-bit RSA pks will be viable, either by govts or corporations with substantial resources?
http://csrc.nist.gov/publications/drafts/nistir-8105/nistir_...
Also relevant is Frederic Jacob's analysis of the NSA's relatively sudden shift towards post-quantum cryptography:
"[It] says that it takes up to 20 years for algorithms to be fully deployed on NSS, and the equipment is often used for 30 years or more. NSA refers to “many experts” that predict a quantum computer capable of effectively breaking public key crypto within that timeframe and that it is important to address that concern."
(as in, the govts know, of course.)