Filippo Valsorda 4/20/2026

Quantum Computers Are Not a Threat to 128-bit Symmetric Keys

Read Original

This article argues that cryptographically-relevant quantum computers pose no real threat to symmetric cryptography algorithms such as AES-128, SHA-2, and SHA-3, despite common misconceptions. It clarifies that Grover's algorithm does not effectively halve security for symmetric keys in practice, due to serial execution constraints and the loss of quadratic speedup when parallelized. The author explains that 128-bit symmetric keys remain safe, and changing key sizes is unnecessary for post-quantum transition. The article cites expert consensus and standardization bodies, aiming to correct misunderstandings that could divert attention from the urgent need to replace vulnerable asymmetric primitives like RSA and ECDH.

Quantum Computers Are Not a Threat to 128-bit Symmetric Keys

Comments

No comments yet

Be the first to share your thoughts!

Browser Extension

Get instant access to AllDevBlogs from your browser

Top of the Week

No top articles yet