3 ms·
The “age of the universe” estimate typically refers to how long it would take to brute force a cipher, i.e. try all possible decryption keys until a valid key i
by sholladay 2y ago
The “age of the universe” estimate typically refers to how long it would take to brute force a cipher, i.e. try all possible decryption keys until a valid key is found. Such attacks are almost never practical because we can’t wait that long. So thinking of encryption this way, comparing encryption algorithms by their brute force resistance, is fairly useless. Instead, most real-world attacks rely on implementation flaws and side-channel attacks, which allow an attacker to make an educated guess or even avoid having to guess in the first place. These vulnerabilities can’t be so easily quantified in terms of how long it will take to break, which is why most algorithms don’t talk about it much in their advertising, even though ease of implementation and side-channel resistance are some of the most important attributes.
However, there are algorithms that do make a concerted effort to mitigate these problems and advertise themselves as such, such as Ed25519.