An>
>> SSL/TLS is 128, and considered plenty secure.
>>
>>Numbers of bits has far less to do with things than some
>> neophytes believe.
>
>The security of a good cryptography system is related to its resistance
>against a brute-force attack, and the computing time for such an attack
>scales with key lenght. But long keys may become unwieldy, so 128 bits
>may be considered plenty for a low-criticality task at hand and 1024
>bits may be necessary for very sensitive data that mustn't be cracked in
>the next, say, forty years.
Please stop posting misinformation, especially after being corrected. As I explained to you before when you claimed that NSA computers can brute-force a 128-bit key, your math is off. *Way* off.
Let's say that in 40 years you can buy a $399 computer at Walmart that has a hundred million processors each running at a hundred gigahertz and able to try a key in one clock cycle.
To check 2^128 keys on such a computer would require roughly
10^12 years -- a hundred times longer than the current age of the universe.
Let's assume that the above computer is somehow made to be
10^12 faster -- bringing the time to crack a key down to a year -- and is built with logic gates that consume the the absolute minimum amount of energy possible (the Von Neumann- Landauer limit). Now assume that checking one key can be done by switching two bits. The power required to run such a computer is roughly a terrawatt -- all the electricity generated everywhere on earth.
Please buy a calculator and learn how to use it before making repeated false claims about how strong a 128-bit key is against a against a brute-force attack.
If you don't believe me and you can't figure out how to work your calculator and do the math yourself, read this:
Or this:
Or this:
Or this:
Or this: