Actually wasn’t the latest gov standard pushing for quantum-resistant algos? I vaguely remember some controversy over it on HN, because the switched recommendation was sudden and came out of nowhere (with at least one suggestion that they must be nearing it, or someone else is). Dont follow this topic normally, which is why I’m so vague on this, and possibly wrong.
Comments
There likely will not be a cryptanalytic capable quantum computer for over a few decades.
I bet that's the NSA's (public) company line
Actually wasn’t the latest gov standard pushing for quantum-resistant algos? I vaguely remember some controversy over it on HN, because the switched recommendation was sudden and came out of nowhere (with at least one suggestion that they must be nearing it, or someone else is). Dont follow this topic normally, which is why I’m so vague on this, and possibly wrong.
If you're talking about NIST, they've initiated the process to standardise post-quantum public key crypto: https://csrc.nist.gov/Projects/Post-Quantum-Cryptography/Pos...
Round 1 submissions were received by November 2017: https://csrc.nist.gov/Projects/Post-Quantum-Cryptography/Rou...
Decades is way too pessimistic. Remember, tech grows exponentially.