🔐 Quantum Computers Are Not a Threat to 128‑bit Symmetric Keys
In a new
article by cryptographer Filippo Valsorda, the core message is clear: quantum computers do not pose a practical threat to 128‑bit symmetric primitives like AES‑128 and SHA‑256, even in optimistic post‑quantum scenarios.
This calls into question the widespread narrative that symmetric key sizes must be doubled just because quantum machines are advancing.
Why 128‑bit is still enoughThe common misconception is that Grover’s algorithm “halves” the effective security of symmetric keys, forcing everyone to jump to 256‑bit.
In reality, Grover offers only a quadratic speed‑up, and its lack of efficient parallelization plus the enormous quantum‑hardware requirements make attacking 128‑bit keys economically and technologically infeasible for the foreseeable future.
What this means for the industryNIST and leading experts agree that 128‑bit symmetric keys remain secure in a post‑quantum world, and the main focus should be on replacing vulnerable asymmetric algorithms (RSA, ECC, classic signatures), not on premature key‑size bloat.
Blockchains and crypto services relying on AES‑128 and SHA‑256 can avoid rushed re‑engineering while still prioritizing post‑quantum migration for key exchange and digital signatures.
#cryptography #quantumcomputing #aes128 #sha256 #blockchain #cybersecurity #postquantum #crypto #quantumsafety