Brute-force attack on 128-bit key

Apr 24, 2008 9 Replies


An>


>> SSL/TLS is 128, and considered plenty secure.
>>
>>Numbers of bits has far less to do with things than some
>> neophytes believe.
>
>The security of a good cryptography system is related to its resistance
>against a brute-force attack, and the computing time for such an attack
>scales with key lenght. But long keys may become unwieldy, so 128 bits
>may be considered plenty for a low-criticality task at hand and 1024
>bits may be necessary for very sensitive data that mustn't be cracked in
>the next, say, forty years.

Please stop posting misinformation, especially after being corrected. As I explained to you before when you claimed that NSA computers can brute-force a 128-bit key, your math is off. *Way* off.


Let's say that in 40 years you can buy a $399 computer at Walmart that has a hundred million processors each running at a hundred gigahertz and able to try a key in one clock cycle.


To check 2^128 keys on such a computer would require roughly


10^12 years -- a hundred times longer than the current age of the universe.

Let's assume that the above computer is somehow made to be


10^12 faster -- bringing the time to crack a key down to a year -- and is built with logic gates that consume the the absolute minimum amount of energy possible (the Von Neumann- Landauer limit). Now assume that checking one key can be done by switching two bits. The power required to run such a computer is roughly a terrawatt -- all the electricity generated everywhere on earth.

Please buy a calculator and learn how to use it before making repeated false claims about how strong a 128-bit key is against a against a brute-force attack.


If you don't believe me and you can't figure out how to work your calculator and do the math yourself, read this:


formatting link


Or this:



formatting link



Or this:



formatting link



Or this:



formatting link



Or this:



formatting link


Guy Macon

Is that why it's called a terrawatt instead of, you know, a terawatt?

No. This is because Landau was renamed to Landauer. The babbling of the ignorants who don't have a clue of what they are talking about.

VLV

I think "Landauer" is, in fact, correct.

formatting link

RL

As in:

[
formatting link
] _Notes on Landauer's principle, Reversible Computation and Maxwell's Demon_ Author: Charles H. Bennett Abstract: Landauer's principle, often regarded as the foundation of the thermodynamics of information processing, holds that any logically irreversible manipulation of information, such as the erasure of a bit or the merging of two computation paths, must be accompanied by a corresponding entropy increase in non-information bearing degrees of freedom of the information processing apparatus or its environment.

formatting link

As for the "babbling of the ignorants who don't have a clue of what they are talking about" comment, I advise the author to do the following simple calculation:

[1] Pick a nice high clock speed such as a thousand gigahertz. [2] Pick an equally high number of processors such as a million. [3] Pick a low number of clock cycles and logic elements to execute a program to test a single key. One, for example.

Start multiplying. 1,000,000,000,000 clock cycles x

1,000,000 processors x 60 seconds x 60 minutes x 24 hours x 365.25 days x 1 cycle per test. Call the result "keys tested."

Raise 2 to the 128th power. Call the result "keys total."

Divide "keys total" by "keys tested."

That's how many years it will take to test all 2^128 keys with the above assumptions. Now try it with more reasonable assumptions.

And yes, calling all the electricity generated everywhere on earth a terrawatt was a play on words. But keep looking; sooner or later you will find a real typo. Spelling flames are *way* more convincing than doing the math yourself and posting the results, right?

You can also do the power calculations yourself. Start here:

formatting link

(The usual disclaimer applies; any post that talks about spelling or calculation errors is likely to contain one or more typos, usually right in the middle of an equation.)

Guy Macon

top posting is just as retarded as a lot of top posting, you top posting Usenet retard!

but it was Calvin and Hobbes, whichis totally excusible.

...that is TERROR-a-watt..

Did you miss krw's post? He explained where the mix up with key lengths arose.

Nope. Saw it and agreed with it.

KRW did correctly explain that you can't compare the keylength of public key cryptography with the key-length needed to resist a brute-force search. I has already explained the difference the last time that Robert Latest posted his misinformation, so the "mix up" is deliberate on his part. It has been explained to Mr. Latest that his math is off by many orders of magnitude, and rather than buying a calculator and doing the math himself, he decided to engage in a personal attack. This is still sci.electronics.design, and designing electronics still requires a certain mindset that includes paying attention when someone tells you that your math is way off. Simply repeating the assertion without proof might work in the political newsgroups, but the actual physical electronics don't respond to emotional arguments or logical fallacies. If he wants to design electronics, he will have to get that calculator and learn how to use it. If he doesn't want to design electronics, he shouldn't be hanging around an electronics design newsgroup wasting the time of those who do.

Join the Discussion

Have something to add? Share your thoughts — no account required.

Didn't find your answer?

Ask the community — no account required