Another option is pastebinning an innocuous message signed with private keys of an implausibly diverse collection of sites and then dropping a link to that in front of a large audience including at least one person who could understand what big of a deal it was.
Either of these is a multi-billion dollar firecracker, of course.
Just because I've figured out the math of factoring large numbers, doesn't mean I'm qualified to make the non-mathematical decision of how to handle that information.
More seriously I would say nothing.
Is the logic of this decision to protect yourself, or to preserve the status quo? If protection, wouldn't the logical decision be to make a full public disclosure and go out of one's way to make it clear that there is nothing more to disclose? In that way, you remove the reason for someone to attack you (unless they are vengeful), as you are no longer "part of the equation" (boom, boom).
There are plenty of powerful people who might think that if you can do this imagine what else you can do. Since you can’t prove that you don’t know anything more it is very risky to tell anyone. Best to keep your mouth shut and let the world know when you are dead.
Perhaps you're thinking that you could make huge $$$ breaking into computers with it. Not really. There are already ways of breaking into many webservers and stealing info and crooks already do this, so we know how profitable / risky it is: not very / very.
https://en.wikipedia.org/wiki/Travelling_Salesman_(2012_film...
All I could think about was how great it would be if someone like Shane Carruth (Primer, Upstream Color) had written/directed it instead.
Though, the full details would more then likely need to be delayed until higher end security improvements could be created. Maybe having the top in mathematics, especially cryptography, quantum mechanics work on creating more secure algorithms to be used.
What I'd do next -- and whether I'd release it -- depends on the public reaction. My first priority would be to light a fire under as many asses as possible, but without hurting anyone.
Convincing a bunch of people you can factor large numbers isn't that hard. And there have been many claimants. But there are security researchers out there that publish lists of numbers to factor of various sizes, including ones (only) they know the factors of, and ones no one knows the factors of.
However, consider what happens if you convince a small number of people you really did it. Most people will either disbelieve it until their bank accounts are emptied, or they will believe it to be no more important than any other security breach.
There are three main groups of people who would understand what it meant. The first are mathematicians who would want to understand the factoring method to push forward their research. The second are Governments and large corporations who depend on factoring for security. The third group are hackers who would want to use it to steal secrets and money.
The second and third group probably wouldn't have your best interests at heart. And many of the first group are working for the second group. So pretty much you should boast about it on conspiracy forums and the like and tell people who don't necessarily understand your accomplishment. At least you'll get a Wikipedia page and people will remember you after you disappear.
Implying John Titor wasn't real! :P
If you found out, someone else almost certainly will as well.
Encryption works because you can double the size of the encryption key and make it take [very large number] times more operations to break the encryption (twice the work to encrypt+decrypt if you have the key, but tremendously harder to crack into without the key).
If RSA was broken, we'd deprecate RSA and move to elliptic curve. Continual advances in factoring and index calculus are in fact the reason we deploy elliptic curve in the first place. Almost every mainstream browser handles it fine.
No matter what happens with factoring, we should all be transitioning away from RSA anyways.
Multiple times over the last 15 years, we've had for all intents and purposes comparable breaks --- BERserk and the original rump session Bleichenbacher e=3 breaks, for instance --- which broke TLS, to the point where you could stand up an evil server and DNS-MITM people to it, and compromise pretty much everyone running (say) Firefox. It wasn't the end of the world. The patch for "integer factorization is solvable in polynomial time" would be slightly more dramatic than the e=3 bug, but not much more: everyone would just deprecate RSA and use ECC.
(apologies to a real mathematician. who. was. also. correct :-))
Oh, and maybe keep using it to factor the keys of whoever I really don't like, and publish them, just to make their life a little more difficult.