Has mainstream cryptography provided 30 years of protection? (Mostly not, but we’re getting way better)
The specific number varies and the idea has been attributed to various sources, but something like “30 years of protection against a really serious attack” is a popular standard for how long we want an encryption algorithm for data that will remain sensitive long‐term to go unbroken. Thus, I wanted to go over the recent (WW2 and onwards) history of cryptography, the year a given algorithm was popularized, and see what has held up for 30 years.
The definition of “popularized” and “broken” are a bit fuzzy, but here I’m defining “popularized” as “the year some (any) standards body described it as a standard”, or for algorithms where there was never a formal specification, “when it shipped in the system that made it widespread”. “Broken” is the first time someone actually recovered a key or plaintext (or for a hash, produced a collision) from data using the given algorithm.
The good news first: no widely used encryption algorithm standardized since 19961, 30 years ago as of writing this, has been broken.
The bad news: most algorithms old enough that 30 years has passed have been broken.
Enigma: Fail
The first Enigma machine was marketed in 1923, initially targeted at private businesses. It is infamous for its use by Nazi Germany during World War II. Much of the famous codebreaking was expedited by operator error, such as the breaks by the Polish Cipher Bureau exploiting the common habit of doubling the message key indicator, but the first known‐plaintext attack by modern definitions against a competent implementation was accomplished in 1940 by the Turing–Welchman bombe.
The Type B Cipher Machine: Fail
The “System 97 Typewriter for European Characters” or “Type B Cipher Machine”, dubbed “Purple” by Americans, was an encryption machine used by the Japanese Foreign Office during World War II. All messages were written in the 26‐character Latin alphabet. The 26 letters were separated by a plugboard into two groups of six and twenty letters. The letters in the sixes group (“sixes”) were scrambled using a 6 × 25 substitution table, while letters in the twenties group (“twenties”) were scrambled using three successive 20 × 25 substitution tables. It was completely broken in 1940, when Genevieve Grotjan found the pattern that exposed how the twenties were encrypted (the sixes fell much earlier).
Lorenz cipher: Fail
The Lorenz SZ40 (and later SZ42), which Bletchley Park called “Tunny”, was a teleprinter cipher attachment used by the German Army High Command for its highest‐level traffic, entering service in 1941. Each 5‐bit teleprinter character was XORed with a key character generated by twelve pinwheels: five “chi” wheels that stepped with every character, five “psi” wheels that stepped irregularly, and two motor wheels that decided when the psi wheels moved. On 30 August 1941 a German operator sent a message of roughly 4,000 characters twice with the same settings and slightly different wording, and John Tiltman used the resulting depth to recover both the plaintext and the keystream. By January 1942 Bill Tutte had worked out the complete logical structure of the machine from that keystream, without anyone at Bletchley having seen one. As with Enigma, the first break leaned on operator error, but Bletchley was reading correctly sent traffic by hand within the year, and from 1944 Colossus automated the attack.
SIGABA: Pass
SIGABA (the Army’s name; the Navy called it ECM Mark II) was the American high‐level cipher machine of World War II, entering service in 1941. It was a rotor machine like Enigma, but where Enigma’s rotors stepped like an odometer, SIGABA had fifteen rotors in three banks of five. One bank enciphered the text, and the other two existed only to generate an irregular stepping pattern for the first, so that between one and four of the cipher rotors moved on every keypress. There is no known break of SIGABA during its service life, which ran into the 1950s. The first practical published attack is George Lasry’s from 2021: a known‐plaintext attack that needs about 100 characters of known text and recovers the key in under 24 hours on a consumer PC. That is 80 years after introduction, and it makes SIGABA the only electromechanical device on this list that did its job.
DES: Fail
The Data Encryption Standard was published as FIPS 46 in January 1977. It was a modified version of IBM’s Lucifer cipher with the key shortened to 56 bits. The key length was criticized immediately (Diffie and Hellman argued that same year that a $20 million machine could search the whole keyspace in about a day), but nobody publicly did it for two decades. In June 1997 the DESCHALL project, a distributed effort using idle time on tens of thousands of computers across the internet, won RSA Security’s DES Challenge by brute force. A year later the EFF’s “Deep Crack”, a purpose‐built machine costing under $250,000, found a key in 56 hours. Twenty years.
A5/1: Fail
A5/1 is the stream cipher that encrypts voice calls on GSM networks, which launched commercially in 1991 (without a published standard). The general design leaked in 1994 and it was fully reverse engineered from a handset in 1999. It combines three linear feedback shift registers of 19, 22 and 23 bits, clocked irregularly by a majority rule, for 64 bits of state (and in early deployments ten of the 64 key bits were simply set to zero). Academic attacks arrived as soon as the design was known, notably Biryukov, Shamir and Wagner’s in 2000, but the first public break anyone could actually use was the A5/1 Cracking Project led by Karsten Nohl, which published roughly two terabytes of rainbow tables in December 2009. With those tables, the session key for a recorded call can be recovered in minutes or less. Despite that, it is still in use wherever 2G is still running.
MD5: Fail
MD5 was published by Ron Rivest as RFC 1321 in April 1992, as a strengthened successor to MD4. It produces a 128‐bit digest, so finding a collision should take about 264 work. Hans Dobbertin found collisions in the compression function as early as 1996, but the first collision in the full hash was announced by Xiaoyun Wang, Dengguo Feng, Xuejia Lai and Hongbo Yu at CRYPTO in August 2004. Twelve years. It got much worse from there: by 2008 chosen‐prefix collisions were good enough to forge a certificate authority, the Flame malware used one to forge a Microsoft code‐signing certificate, and today a collision takes under a second on a laptop.
RC4: Fail
RC4 was designed by Ron Rivest in 1987 and kept as a trade secret by RSA Data Security until someone anonymously posted source code for it to the Cypherpunks mailing list in 1994. There was never a formal specification, so I’m going to count from 1995, when it shipped in Netscape’s SSL. It is about as simple as a cipher gets: a 256‐byte permutation that is shuffled by the key and then swapped around one pair at a time to produce keystream. The first key recovery came in 2001, when Fluhrer, Mantin and Shamir showed that WEP’s habit of prepending a public IV to a fixed key leaked that key through the first bytes of output, and Stubblefield, Ioannidis and Rubin implemented it against real hardware within weeks. If you would rather not blame RC4 for WEP, plaintext recovery against RC4 in TLS followed in 2013, and by 2015 RC4 NOMORE could decrypt a cookie in about 75 hours. Six years, or eighteen if you are generous.
RSA-512: Fail
RSA itself dates to 1977, but its security depends entirely on the size of the modulus, so I am treating each common key size as its own entry. The Privacy Enhanced Mail standard, RFC 1423 from February 1993, allowed moduli from 508 to 1024 bits, and 512 bits was both a common default and the most that US export rules permitted in SSL. In August 1999 a team led by Herman te Riele factored RSA-155, a 512‐bit challenge number, using the general number field sieve on about 300 workstations plus a Cray for the matrix step. Six years. By 2015 the “Factoring as a Service” project was doing the same thing in under four hours for $75 of rented cloud time, and enough servers still accepted export‐grade 512‐bit keys to make the FREAK attack work.
RSA-1024: Pass
The same RFC 1423 set 1024 bits as its upper limit in 1993, and 1024 went on to be the default nearly everywhere until NIST disallowed it after 2013. Thirty‐three years later nobody has publicly factored a 1024‐bit RSA modulus, so it is a pass. It is technically still standing, but I would expect a break as soon as anyone cares enough to cough up the money for GPU time. The public factoring record was at 829 bits (RSA-250) from February 2020 until last month, when it moved twice in sixteen days. Eric Lu factored the 862‐bit RSA-260 on 3 September 2026 and Stephen Weis factored RSA-896 on 19 September, both using GPU ports of the number field sieve written largely by AI coding agents. Scaling from those runs puts a 1024‐bit factorization at roughly 1,000 GPU‐years, or about $30 million. Separately, a team led from UC San Diego forged 1024‐bit RSA signatures without factoring anything, although that attack first needs about 232 queries to a raw signing oracle. If you count that as a break, RSA-1024 fell at 33 years. Either way, it cleared 30.
SHA-1: Fail
SHA-1 was published by NIST as FIPS 180-1 in April 1995. It is a one‐rotation fix to the original SHA from 1993 (now called SHA-0), which the NSA withdrew over a flaw it did not describe. The digest is 160 bits, so a collision should cost about 280. In 2005, Xiaoyun Wang, Yiqun Lisa Yin and Hongbo Yu showed a theoretical attack at 269, and the estimates kept dropping, but an actual collision took until February 2017, when Marc Stevens and a team from CWI and Google published SHAttered, showcasing two different PDFs with the same SHA-1 hash. It was found with about 263 SHA-1 computations (6,500 CPU‐years plus 110 GPU‐years). Twenty‐two years, the closest fail on this list.
3DES: Fail
Triple DES runs DES three times with two or three independent keys, which fixes the 56‐bit key problem while reusing all the existing DES hardware. The idea is nearly as old as DES itself, but as a standard for general use I am dating it to RFC 1851 in 1995. Nobody has recovered a 3DES key, and with three keys the best generic attack still costs about 2112. 3DES inherits the same weakness from DES, the 64‐bit block. In August 2016, Karthikeyan Bhargavan and Gaëtan Leurent published Sweet32, which relies on the fact that CBC mode starts leaking plaintext once about 232 blocks have been encrypted under one key. They recovered an HTTPS session cookie from a 3DES connection after capturing 610 GB of traffic over 30.5 hours. Twenty‐one years. NIST disallowed 3DES for encryption after 2023.
ECC P-256: Unbroken so far (26 years and counting)
P-256 (also called secp256r1 or prime256v1) is the 256‐bit elliptic curve that NIST standardized in FIPS 186-2 in 2000, and it still handles a large share of the key exchanges and signatures on the internet. The best public attacks on elliptic curve discrete logs are still the generic ones. The record for a prime‐field curve is 112 bits, set in 2009 on a cluster of PlayStation 3s, and since the work doubles with every two bits of curve size, 256 bits is about 272 times further away. The standing complaint about P-256 is the unexplained origins of the seed its parameters were generated from, though 26 years of looking has not turned up a weakness. The real threat is Shor’s algorithm. Estimates of the quantum computer needed to break a 256‐bit curve fell sharply this year, from under 500,000 superconducting qubits running for minutes (Google, March) to about 20,000 trapped‐ion qubits running for 26 days (IonQ, September). Neither machine exists. P-256 needs to last until 2030 to pass.
AES: Unbroken so far (25 years and counting)
Rijndael, by Joan Daemen and Vincent Rijmen, won NIST’s open competition and became the Advanced Encryption Standard as FIPS 197 in November 2001. The change in processes spurred by that competition is probably the biggest single reason this part of this list looks different from the first: candidates are made public before they are used and must prove themselves against open attacks. No more designs handed down from above. The best attack on the full cipher is the 2011 biclique attack by Bogdanov, Khovratovich and Rechberger, which recovers an AES-128 key in 2126.1 operations instead of 2128, which is a minimal change. Attacks that do real damage still stop at 7 of AES-128’s 10 rounds, where they have been stuck for over a decade (one of them got 200 to 800 times cheaper this July and is still nowhere near practical). The real‐world breaks have all been implementation error, mostly cache‐timing side channels, which hardware AES instructions have been cleaning up. It needs to reach November 2031.
SHA-256: Unbroken so far (24 years and counting)
SHA-256 is part of the SHA-2 family, published in FIPS 180-2 in August 2002. Structurally, it is a bigger and more complicated relative of MD5 and SHA-1, which is why people got nervous after Wang’s attacks and why NIST ran the SHA-3 competition as insurance. The insurance has not been needed. From 2013 until this year the best collision attack reached 31 of SHA-256’s 64 steps. That has finally started to move: 2026 papers reach 37 and then 38 steps in theory, and 35 steps with an actual colliding pair. Things are moving, but it still leaves 26 steps untouched. It needs to reach 2032.
RSA-2048: Unbroken so far (21 years and counting)
2048‐bit RSA keys have been possible for as long as anyone has had the patience to generate them, but the date I am using is 2005, when NIST’s SP 800-57 told everyone to be off 1024 bits and onto 2048 by the end of 2010. Classically it is nowhere near broken. The record is the 896‐bit factorization from last month, and under the usual number field sieve scaling 2048 bits is about 35 billion times more work than that, so the September records make RSA-1024 nervous but RSA-2048 not at all. The threat is Shor’s algorithm again. Craig Gidney’s 2025 estimate is that a quantum computer with under a million noisy qubits could factor a 2048‐bit modulus in under a week, down from 20 million qubits in his 2019 estimate with Martin Ekerå, and no machine close to that size exists. By my dating, RSA-2048 would pass in 2035, which is also the year NIST’s draft transition plan disallows it.
ChaCha20: Unbroken so far (11 years and counting)
ChaCha is Daniel J. Bernstein’s 2008 refinement of his earlier Salsa20, and it became a standard in 2015 with RFC 7539, after Google had already deployed it in Chrome and Android as the fast option for phones without AES hardware. It is built entirely from 32‐bit additions, rotations and XORs, which makes it easy to implement in constant time and sidesteps the cache‐timing attacks that hurt AES in software. It’s remarkably secure for how simple and fast it is. The best public attacks reach a little over 7 of its 20 rounds, at a cost of around 2148 against a 256‐bit key. It has until 2045.
ML-KEM: Unbroken so far (2 years and counting)
ML-KEM, known as CRYSTALS-Kyber before NIST renamed it, was standardized as FIPS 203 in August 2024. Its security rests on the module learning with errors problem: roughly, recovering a secret from many noisy linear equations over a polynomial ring. It looks pretty good: lattice problems have been studied since the 1990s, Kyber came through seven years of public cryptanalysis in the NIST process, and the breaks so far have been of implementations (the KyberSlash timing leaks) and not the algorithm. On the other hand, that same process saw SIKE broken in about an hour on a single core and Rainbow broken over a weekend on a cheap classical computer, both in 2022 and both late in the process, and this July the lattice‐based signature candidate HAWK was withdrawn a day after an attack roughly halved the lattice problem an attacker has to solve. None of those attacks touch ML-KEM.
The tally
Of those old enough to judge, two passed: SIGABA, and, barely, RSA-1024. The other ten failed.
The current ones (P-256, AES, SHA-256, RSA-2048, ChaCha20 and ML-KEM) haven’t been broken yet. The way things are going, it’s looking more likely that P-256 and RSA-2048 will fall to quantum computers rather than new cryptanalysis insights.