On 2026-10-01 members met to discuss why NIST is deprecating in 2030 and disallowing in 2035 several cryptography algorithms and moving to new quantum resistant ones.
It seems less clear than it immediately looks. Firstly RSA and Elliptic Curve algorithms are severely at risk of being decrypted by a quantum computer due to Shor’s algorithm. AES seems less so, Grover’s algorithm theoretically applies a square root on the difficulty (2^128 becomes 2^64), however the expectation is that qubit-ops won’t match the performance of bit-ops for a long time, by many orders of magnitude. So while NIST recommends against the use of AES-128 we identified it was still pretty hard to crack allowing IOT devices to retain encryption capabilities at low compute power.
The main reason for setting the deadlines is “Record Now, Decrypt Later”, an issue where data that is still relevant in 10 years time may become the target of large (state-level) quantum computer attacks.
We did get an introduction to ML-KEM and ML-DSA, lattice based asymmetric algorithms. The main takeaway is that every signed message now grows from 64 bytes for ECDSA, up to 2420 bytes for the smallest ML-DSA category. So even when we get accelerators, the overhead will still be significant. This will overall make the internet a more congested space by several orders of magnitude.
