Well, we cheated a bit This isn't really true, since computers get faster over time A better strategy for breaking 128-bit crypto is just to wait until computers get 2^88 times faster, then break it on one computer in 3 days. How long do we wait? Moore's law says 132 years. If we believe Moore's law will keep on working, we'll be able to break 128-bit crypto in 132 years (and 3 days) :-) An even better strategy: don't break the crypto at all! There are always weaker parts of the system to attack More on this later