It also saves a lot of time answering questions and justifying the choice.
So, IMHO, go for 256 bits and be done with it.
It also saves a lot of time answering questions and justifying the choice.
So, IMHO, go for 256 bits and be done with it.
For the few who do object, explaining that there is no such thing such as parity between symmetric and asymmetric primitive can help: https://loup-vaillant.fr/tutorials/128-bits-of-security
Besides, we know the next step: use Curve448 to stave off criticism about using a small curve, and then people start talking quantum computers.
Edited as not AES but you get the point taking into account that AES256 is the standard.
128 bits however is humanly achievable (35 years worth of peak Bitcoin mining), and as such perhaps a tad low in really high stakes scenarios (say highly classified stuff).
We could chose something between 128 and 256, but they're nice powers of two, and we tend to like powers of two.
Current bitcoin miner can provide efficiency of 19 000 000 MH/J or 19e12 H/J. If we would assume bruteforcer can perform with the same efficiency, we would need 1.6e16 J/s = 16 000 TW.
Current humanity energy output is something like 17 TW.
With your numbers if humanity dedicated all its energy to brute forcing a 128/bit key for a year it would have a ~0.1% chance of finding it. I guess that's a pretty good argument that no one is going to even try it in the foreseeable future.
See this cousin comment highlighting my error. that out: https://news.ycombinator.com/item?id=34955855