4 ms·
Did you read the post? This is specifically addressed. The AES hardware support requires a bunch of die area specifically for that purpose and still isn't that
by apendleton 10y ago
Did you read the post? This is specifically addressed. The AES hardware support requires a bunch of die area specifically for that purpose and still isn't that performant. Smaller-area CPUs don't spend the area and perform abysmally on AES, and even in CPUs that do include AES-NI, Chacha achieves comparable performance for the same security margin without any custom hardware support, just using the general vector instructions added to improve game performance. DJB expects that because vector math continues to improve while AES hardware does not, Chacha will soon outperform AES even on devices with hardware support.
- tptacek 10y agoI agree with the comment, but it would be better without that first sentence.
- nitwit005 10y agoThank you for pointlessly regurgitating much of his post? The fact that Intel put an encryption feature in their chip, which does indeed make that algorithm faster, would tend to indicate they wanted faster encryption wouldn't it? That some other algorithm could be faster still isn't really contradicting that.
- brohee 10y agoI'd wager that the goal wasn't so much speed (which is very rarely the issue) but security. It was way too hard to program a constant time AES implementation without AES-NI.