Comment by ls612
What is the state of PQ symmetric crypto? My layman's understanding is that 128 bit AES is known to be broken by a quantum computer and that 256 AES may be OK but that isn't certain? Is this an additional vector for the "harvest and wait" strategy in the future?
128-bit AES is fine. To run Grover’s algorithm against it you’d need to cover the moon with qubits.