1. it's reasonable to assume the NSA is a decade ahead and has more computers than academia.
2. you want your secrets to last a decade (or longer)
3. the total amount of data you're encrypting per client is only 256 bits anyway (the size of a symmetric key) so the absolute performance impact is relatively minimal
1. it's reasonable to assume the NSA is a decade ahead and has more computers than academia.
2. you want your secrets to last a decade (or longer)
3. the total amount of data you're encrypting per client is only 256 bits anyway (the size of a symmetric key) so the absolute performance impact is relatively minimal