DES is a cautionary tale in cryptography. It was the official U.S. government encryption standard for over 20 years, trusted by banks, governments, and militaries worldwide. Then it was broken — not by a mathematical breakthrough, but by brute force. The story of DES is the story of why key size matters, why no encryption lasts forever, and why the cryptography community now designs algorithms with much larger key spaces.
What DES Is
DES (Data Encryption Standard) is a symmetric-key block cipher that operates on 64-bit blocks of data using a 56-bit key. It was developed in the 1970s by IBM (based on an earlier design called Lucifer by Horst Feistel) with modifications from the U.S. National Security Agency, and was adopted as a federal standard in 1977 as FIPS PUB 46.
For two decades, DES was the symmetric encryption algorithm. It was used in ATM PIN encryption, banking networks, government communications, and the early internet. Every serious cryptographic system in the 1980s and 1990s used DES or a variant of it.
How DES Works
DES is a Feistel cipher — a specific structure where the input block is split into two halves, and each round applies a function to one half before swapping them. This structure has an elegant property: the encryption and decryption processes use the same algorithm, just with the subkeys applied in reverse order.
### The Feistel Structure
DES processes data in 16 rounds. In each round:
1. The 64-bit input block is split into a left half (L) and a right half (R), each 32 bits. 2. A round function F is applied to R using a 48-bit subkey derived from the 56-bit master key. 3. The output of F is XORed with L. 4. L and R are swapped for the next round.
After 16 rounds, the halves are recombined to produce the 64-bit ciphertext block. Decryption applies the same process with the subkeys in reverse order.
### The Key Schedule
The 56-bit key (note: DES keys are stored as 8 bytes, but one bit per byte is a parity bit, leaving 56 effective key bits) is expanded into 16 different 48-bit subkeys, one for each round. The key schedule uses permutation and rotation operations to derive these subkeys.
### The F Function
The round function F takes a 32-bit half-block and a 48-bit subkey. It expands the 32-bit input to 48 bits using a permutation, XORs it with the subkey, then passes the result through eight substitution boxes (S-boxes). The S-boxes are the heart of DES's non-linearity — they are the only step where the output is not a linear function of the input. The S-box output is 32 bits, which goes through a final permutation.
### Block Size and Mode
DES encrypts 64-bit blocks. To encrypt data longer than 64 bits, DES is used in a mode of operation — historically CBC (Cipher Block Chaining) or ECB (Electronic Codebook). ECB is insecure because identical plaintext blocks produce identical ciphertext blocks. CBC chains each block with the previous ciphertext block to prevent this pattern. Neither mode provides authentication. For more on modes, read our AES-GCM vs AES-CBC comparison.
Why DES Is Broken
The fatal flaw of DES is its key size: 56 bits. The key space is 2^56, which is approximately 7.2 x 10^16 possible keys. In 1977, this was considered adequate — the computing power required to try all keys was beyond the reach of any adversary except perhaps the NSA.
By the 1990s, this was no longer true.
### The EFF DES Cracker (1998)
The Electronic Frontier Foundation built a machine called the EFF DES Cracker (also known as "Deep Crack") for $250,000. It contained 1,856 custom ASIC chips, each capable of testing 90 million keys per second. The machine could try the entire 56-bit key space in approximately 56 hours, with an average crack time of about 23 hours.
This was a watershed moment. A non-government organization, on a modest budget, had demonstrated that DES was breakable by brute force. The message was clear: 56 bits was no longer enough.
### COPACOBANA and Later Hardware
In 2006, researchers built COPACOBANA (Cost-Optimized Parallel Code Breaker), a machine using 120 FPGA chips that could crack a DES key in about 6.4 days for under $10,000. By the 2010s, cloud computing and GPU clusters made DES cracking accessible to anyone with a credit card. A DES key can now be brute-forced in hours for a few thousand dollars, or in minutes if you invest in specialized hardware.
### The Mathematical Reality
The difference between 2^56 and modern key spaces is staggering:
| Algorithm | Key Size | Key Space | Time to Brute Force | | --- | --- | --- | --- | | DES | 56 bits | 7.2 x 10^16 | Hours (specialized hardware) | | 3DES (2-key) | 112 bits | 5.2 x 10^33 | Theoretical, vulnerable to meet-in-the-middle | | AES-128 | 128 bits | 3.4 x 10^38 | Beyond current technology | | AES-256 | 256 bits | 1.2 x 10^77 | Beyond any imaginable technology |
Each additional bit doubles the key space. The gap between 56 bits and 256 bits is a factor of 2^200 — a number so large that analogies fail. AES-256 is not merely harder to crack than DES. It is harder by a margin that exceeds the number of atoms in the observable universe.
3DES: The Stopgap That Became a Problem
When DES was clearly broken, the immediate response was 3DES (Triple DES). Instead of designing a new algorithm, 3DES applies DES three times in sequence:
Encrypt with Key 1, Decrypt with Key 2, Encrypt with Key 3 (EDE mode).
With three independent keys, 3DES provides 168 bits of nominal security. However, a meet-in-the-middle attack reduces the effective security to approximately 112 bits. The most common deployment uses two keys (K1 = K3), providing 112 bits of security.
3DES bought time, but it introduced two problems:
Performance. 3DES is three times slower than DES and roughly 100 times slower than AES in software. In hardware, AES with native CPU instructions (AES-NI) is even faster relative to 3DES.
Block size. 3DES uses the same 64-bit block size as DES. At 64 bits, the birthday bound — the point at which you expect a repeated block due to the pigeonhole principle — is reached after encrypting approximately 2^32 blocks (about 32 GB of data). Beyond this point, CBC mode leaks information. AES uses a 128-bit block size, where the birthday bound is 2^64 blocks — far beyond any practical data volume.
NIST deprecated 3DES in SP 800-131A, disallowing it for new applications and setting 2023 as the deadline for disallowance in existing applications, with full disallowance by 2024. The payment card industry followed suit, with PCI DSS requiring migration away from 3DES.
What Replaced DES: The AES Competition
In 1997, NIST announced a public competition to select a replacement for DES. Unlike the DES selection process (which was conducted largely behind closed doors with NSA involvement), the AES competition was open, transparent, and international.
Fifteen algorithms were submitted from twelve countries. Over three years, the cryptographic community analyzed the candidates for security, performance, and implementation characteristics. Five finalists were selected: MARS, RC6, Rijndael, Serpent, and Twofish.
In October 2000, NIST selected Rijndael, designed by Belgian cryptographers Joan Daemen and Vincent Rijmen, as the Advanced Encryption Standard. Rijndael was chosen for its combination of security, performance across hardware and software platforms, and implementation simplicity. AES was published as FIPS 197 in 2001.
AES supports three key sizes: 128, 192, and 256 bits. It uses a 128-bit block size and operates in 10, 12, or 14 rounds depending on the key size. AES is not a Feistel cipher — it uses a substitution-permutation network structure.
For a detailed explanation of how AES works, read our AES-256-GCM explainer. For the differences between AES modes, see AES-GCM vs AES-CBC.
Practical Migration: If You Encounter DES Today
DES and 3DES still exist in legacy systems. If you find DES in a system you maintain, treat it as a security vulnerability:
Identify where DES is used. Check encryption configurations in databases, network protocols, payment systems, and old hardware appliances. Banking networks and ATM infrastructure have historically been slow to migrate.
Assess the risk. DES-encrypted data is not encrypted in any meaningful sense — it can be decrypted by an attacker with modest resources. 3DES-encrypted data is stronger but slow and approaching deprecation. Any data encrypted with DES or 3DES should be considered at risk.
Migrate to AES-256. Replace DES/3DES with AES-256 in GCM mode. AES-256-GCM provides authenticated encryption, meaning it simultaneously encrypts the data and verifies its integrity. This is a significant improvement over DES in CBC mode, which provides no integrity protection.
Re-encrypt existing data. Decrypt data with the old algorithm and re-encrypt with AES-256-GCM. This requires access to the existing keys, so do it before the old system is decommissioned.
Update key management. DES keys are 56 bits (7 bytes with parity). AES-256 keys are 32 bytes. Ensure your key management infrastructure supports the larger key size.
You can encrypt data with AES-256 right now using the AES text encryptor or encrypt files with the file encryptor, both of which use AES-256-GCM.
The Lesson of DES
DES teaches two lessons that remain relevant:
Key size matters more than algorithm complexity. DES's S-boxes, Feistel structure, and round function are cryptographically sophisticated. None of it matters when the key space is small enough to brute-force. An algorithm with a large key space and simple structure (like AES) is more secure than an algorithm with a complex structure and a small key space.
Cryptography has a shelf life. Algorithms that are secure today may not be secure in 20 years as computing power increases and cryptanalytic techniques improve. The DES-to-AES transition took over a decade. The cryptography community is already working on post-quantum cryptography (NIST PQC standardization) to prepare for the eventuality that quantum computers break RSA and ECC. Planning for algorithm migration is a normal part of security engineering, not a sign of failure.
For the broader context of how DES fits into the symmetric encryption landscape, read our symmetric vs asymmetric encryption guide. For how symmetric encryption combines with asymmetric encryption in real systems, see hybrid encryption. And for the fundamental distinction between one-way hashing and two-way encryption, read hashing vs encryption.