pull down to refresh
Well, there's the Grover speedup, which should eventually be relevant to things like AES (not anytime soon). But even then, we could just switch to AES256 and have as much security as before. It's not fundamentally broken by quantum computers in the way that RSA, Diffie-Hellman, or elliptic curve crypto are (with the underlying problems solvable in quantum polynomial time).
reply
AES 128 is fine in a post-quantum world?