"NM" == Niels Möller nisse@lysator.liu.se writes:
NM> Does anyone else know of use or interest in 128-bit chacha keys?
Given DJB's paper¹ on parallel hardware cracking, which strongly suggests against using 128 bit symmetric if one is concerned about well funded adversaries, I doubt there are any.
1] IINM, I'm thinking of http://cr.yp.to/snuffle/bruteforce-20050425.pdf
-JimC -- James Cloos cloos@jhcloos.com OpenPGP: 1024D/ED7DAEA6