Also, there's no other way to get the message to Snowden unless you give it publicity. If he browses the Internet for news, he will find there's a message from Wired for him.
For a back-of-the-envelope cost estimate, I'm going to assume that there have been no major theoretical breakthroughs in the last couple of years, and that the machines they used were roughly equivalent to an EC2 "medium" instance. That puts the cost of breaking a 768-bit key, using spot instances for cost-efficiency, at about US$200k.
That sounds small, but encryption/decryption are still reasonably efficient with larger keys, while factorization becomes vastly harder. Breaking a 2048-bit key would take something like 200 quadrillion dollars worth of CPU time. A 4096-bit key, like the one used for this message, would be vastly more secure than that.
Remember, the NSA's mandate is twofold: They are a signals intelligence agency, but they are also charged with protecting government communications, much of which occur with commercially-available cryptography.
RSA does make people nervous for some valid reasons, and that's why there's a gradual transition to ECC underway, but there's little reason to expect a practical attack on RSA at 2048+ bits in the near term.
Absent an operational error on the part of Wired or Snowden, I seriously doubt the NSA will be decrypting that message in Snowden's lifetime, and almost certainly not before changes in the political climate.
That's a lot of doublings of the difficulty to brute force a key. 2^3328 increase in difficulty.
$ gpg --keyserver pgp.mit.edu --recv-keys 79DEBE35
$ gpg --encrypt --sign --armor --recipient 79DEBE35
and post it publicly; perhaps on Pastebin.[1]: http://www.washingtonpost.com/world/national-security/code-n...
*assuming you believe the key is authentic
Edit: Also, it's not very hard to generate a different key with signature 79DEBE35, and put it on the key servers. gpg's displaying of such short abbreviations for keys is one the worst parts of its UI.
How do you know this?
It's still "my" key even though you're signing or rather encrypting a message with it.
We don't know who that key belongs to for sure, of course, but it could be Snowden's.
EDIT: While what I said was technically true, in that it is encrypted with the 79DEBE35 key, that's not Wired's key, it's the recipient's key.
Yup: http://www.asheesh.org/note/debian/short-key-ids-are-bad-new...