23 karma · joined December 9, 2024
While it's true that there are less opportunities to track you through leaky / malicious apps, "dumbphones" remain, well, phones, with data retention laws in almost all countries in the world (and the subsequent leaks / hacks, see the recent Salt typhoon events for a good example) plus extra vulnerabilities due to poorly-developed Operating Systems.
Unfortunately, this is comparing apples to oranges because AES-256-GCM is authenticated, so you will need a MAC with ChaCha12 (usually Poly1305) which finally makes ChaCha12 in AEAD mode slower than AES-256-GCM.
But the real question is: What is fast enough?
I believe that between 1 and 2 GB / s per core for an AEAD is fast enough as I/O will be your bottleneck way before that.
This is why I will always favor a ChaCha20/ChaCha12-based AEAD over AES and its many footguns.
It's time to shift priorities.
Edit: It focuses too much on the language instead of the ecosystem.