[Cryptography] recommending ChaCha20 instead of RC4 (RC4 again)

Peter Gutmann pgut001 at cs.auckland.ac.nz
Thu Mar 13 00:14:18 EDT 2014

<dan at geer.org> writes:

>Back to the conference room and the sales cycle, how many, many times I've
>had some prospective customer say something like "10% performance hit for
>security? That's a deal breaker!"
>My answer: "Well, 10% is 2.5 months' worth of Moore's Law..."

Unless it's the embedded world (which makes the PC and phone and whatnot
market seem trivial by comparison), in which performance stays constant and
cost goes down.  Ten years ago your code had to run on a Cortex-M.  Ten years
from now your code will need to run on more or less the same Cortex-M, only
it'll be cheaper and have more integrated peripherals.


