Plenty principle

Security is a budget, not a sacred number.

State the threat, cross it with room to spare, then notice when an algorithm—not entropy—becomes the limiting component.

Hands-on evidence

Build a Plenty budget

Name the attacker, give them time, add a margin, and stop when another limit takes over.

2^10 (1,024)
10 years
+32 bits
128 bits
Plenty

The effective strength clears both the threat model and the chosen margin.

Threat budget68.1 bitsrate × parallelism × time
Plenty Line101 bitsthreat + 32-bit margin
Effective strength128 bitsentropy and algorithm match
Guessing success bound≈ 2^-60simplified uniform-search model
Where should you stop?

You crossed the chosen margin. More entropy may add complexity without improving this threat model.

The rates are transparent teaching scenarios, not claims about a particular current GPU, password hash, or cipher. Real guess rates depend on the exact operation.