50 ms·
I am in now way a crypto expert, just someone who enjoys casually reading about it. But in my mind even a security for speed trade off can be worthwhile. Otherw
by thmsths 1y ago
I am in now way a crypto expert, just someone who enjoys casually reading about it. But in my mind even a security for speed trade off can be worthwhile. Otherwise the alternative is often: no crypto at all because it won't run on that tiny MCU and we don't have the budget for a hardware accelerator.
- Taek 1y agoEven the tiniest MCU can typically perform more than one cryptographic operation per second. If your MCU has any cycles to spare at all it usually has enough cycles for cryptography. If you don't have any cycles to spare, you can upgrade to an MCU that does have cycles to spare for less than $0.50 in small batches, and an even smaller price delta for larger batches. Any device that doesn't use cryptography isn't using it because the manager has specifically de-prioritized it. If you can't afford the $0.50 per device, you probably can't afford the dev that knows his way around cryptography either.
- Sanzig 1y ago> Even the tiniest MCU can typically perform more than one cryptographic operation per second. If your MCU has any cycles to spare at all it usually has enough cycles for cryptography. Well, no. If you can do 1 AES block per second, that's a throughput of a blazing fast 16 bytes per second. I know that's a pathological example, but I do understand your point - a typical workload on an MCU won't have to do much more than encrypt a few kilobytes per second for sending some telemetry back to a server. In that case, sure: ChaCha20-Poly1305 and your job is done. However, what about streaming megabytes per second, such as an uncompressed video stream? In that case, lightweight crypto may start to make sense.
- tptacek 1y agoThis whole framing is weird, because you can't spend $0.50 per already-deployed part to upgrade to something that can viably do AES.
- deleted 1y ago[deleted]
- Taek 1y ago1 operation per second would refer to cryptographic signatures. If you are doing Chacha, the speeds are more like 1 mbps. AES is probably closer to 400 kbps. An uncompressed video stream at 240p, 24 frames per second is 60 mbps, not really something an IoT device can handle. And if the video is compressed, decompression is going to be significantly more expensive than AES - adding encryption is not a meaningful computational overhead.
- HeatrayEnjoyer 1y agoIf it's compressed you don't need to decompress it first.
- dylan604 1y agoon the receiving end.
- yardstick 1y agoThe device doing the decryption may not be the same device that does the decompression. Eg a small edge gateway could be doing the VPN, while the end device is decoding the video.
- dylan604 1y agoA VPN’s encryption is different than a streaming platform’s encryption. The streamer’s encryption is their form of rights management. So the device/app decompressing the video very much is the point of decryption. If not, the rights management is very broken. If the small edge gateway is somehow decrypting the video stream, you’d have a very rogue device that lots of people would be curious to learn more
- yardstick 1y agoCCTV doesn’t need rights management. Nor do advertising billboards.
- wakawaka28 1y ago>If you don't have any cycles to spare, you can upgrade to an MCU that does have cycles to spare for less than $0.50 in small batches, and an even smaller price delta for larger batches. The monetary cost is most likely not the problem. Tacking on significant additional work is bound to consume more power and generate heat. Tiny devices often have thermal and power limits to consider.
- adgjlsfhk1 1y agoThe problem is it isn't significant work. You can perform ChaCha8 on pen and paper in ~30 minutes. It's literally 768 single cycle 32 bit integer operations.
- wakawaka28 1y ago768 single cycle instructions to do WHAT? To encode a few bytes or something? You can't convince me that the cost of cryptography is never prohibitive. Boldly asserting that your idea of "significant work" is universal for all applications isn't going to convince me, nor are weird anecdotes about tangentially related things.