3 ms·
When you say "get their asses kicked", you mean in terms of performance right? Both sets of cryptography are secure under the same set of assumptions, it's just
by Taek 1y ago
When you say "get their asses kicked", you mean in terms of performance right? Both sets of cryptography are secure under the same set of assumptions, it's just that one is more performant on limited instruction sets and the other is more performant on full featured instruction sets?
- tptacek 1y agoI'm saying that AES isn't viable a decent-sized chunk of existing embedded hardware, and that the constructions that are viable on those platforms both (1) fall below the security thresholds of front-line mainstream constructions like AES-GCM or Chapoly and (2) would in fact be slower that AES or Chapoly on modern workstation, server, and phone platforms. Hardware capabilities vary widely; there isn't one optimal algorithm that fits (or, in the case of MCUs, is even viable) on every platform. What's worse, efforts to shoehorn front-line mainstream constructions onto MCUs often result in insecure implementations, because, especially without hardware support (like carryless multiplication instructions), it's very difficult to get viable performance without introducing side channels.
- throw0101a 1y ago> When you say "get their asses kicked", you mean in terms of performance right? Depends on what you mean by "performance". It could be latency: high frequency traders (HFTs) could probably be happy if their order data is protected for "only" an hour if it means dropping latency from (e.g.) 42 nanoseconds down to 24. An hour ago for some trading platforms is stale as a decade ago.