I was “following key length recommendations” 10 years ago that said 3072 bit or higher for RSA. At that time, lightweight processors would struggle a bit with 4096 bit keys, so I’ve launched a fair number of systems with 3072 bit keys - none of the data on any of them is worth a handful of months on a CPU cluster.
Though, there is an interesting metric you can put on key value today, because so much compute is available for short term lease, you can literally spend $1m for a 50/50 shot at cracking a “very secure” key in a few hours, because you pay per unit of compute, not per hour. Now, Amazon or whoever might start refusing your business if you tried to spend $1M on compute in parallel all running within a single hour, but you could probably negotiate with them to get that done in low demand slots over a couple of days.
I was “following key length recommendations” 10 years ago that said 3072 bit or higher for RSA. At that time, lightweight processors would struggle a bit with 4096 bit keys, so I’ve launched a fair number of systems with 3072 bit keys - none of the data on any of them is worth a handful of months on a CPU cluster.
Though, there is an interesting metric you can put on key value today, because so much compute is available for short term lease, you can literally spend $1m for a 50/50 shot at cracking a “very secure” key in a few hours, because you pay per unit of compute, not per hour. Now, Amazon or whoever might start refusing your business if you tried to spend $1M on compute in parallel all running within a single hour, but you could probably negotiate with them to get that done in low demand slots over a couple of days.