3 ms·
There's no contradiction. It doesn't really matter which you use under most threat models. AES-128 gets you guaranteed AES-NI on virtually all processors sold
by CiPHPerCoder 8y ago
There's no contradiction.
It doesn't really matter which you use under most threat models.
AES-128 gets you guaranteed AES-NI on virtually all processors sold in the past decade. AES-256 gets you better assurance against quantum attackers, should they ever become a real threat.
You can side-step both of these by just using a ChaPoly ciphersuite which is constant-time and fast on all platforms, without hardware acceleration. (If you ecide to just use libsodium's box/secretbox, as Thomas said in another comment, you're doing this side-step... which is thematically appropriate for a cipher named after a Latin dance).