I did Shor, so let’s look at Grover’s — w00t.
I did Shor, so let’s look at Grover’s — w00t.
(PQC FUD edition: why your AES isn’t spontaneously combusting)
There’s fresh fear-mongering about Grover’s algorithm “breaking AES.” Breathe. Grover is a quadratic speedup for brute force, not a magic AES disintegrator.
What Grover actually does (no vibes, some math):
Classical key search: ~2^k tries.
Grover key search: ~2^(k/2) quantum iterations if you can build a reversible AES oracle and run it fault-tolerantly zillions of times.
Translation: AES-128 ≈ 64-bit quantum security (too small for long-term secrecy). AES-256 ≈ 128-bit quantum security (still strong).
What it does not do:
It doesn’t “break” AES structure—just speeds up dumb search.
It doesn’t help without a known plaintext–ciphertext pair for the oracle.
It doesn’t affect modes or block sizes; it only targets the key.
It doesn’t run at scale today; you’d need a huge, fault-tolerant QC with AES circuits and error correction on repeat.
So what’s worth doing (and saying) right now?
Use AES-256 for data that needs a long shelf life.
For hashes, remember: Grover makes n-bit preimage ≈ 2^(n/2); plan accordingly (e.g., SHA-256 still fine).
Save your urgency for public-key: Shor is the one that kneecaps RSA/ECC. That’s why we ship PQC (Kyber/Dilithium), hybrid KEMs, and, above all, crypto-agility.
How to de-FUD a meeting in one breath:
“Grover halves effective key bits; AES-256 remains robust. Our quantum risk is mainly public-key, so we’re migrating to PQC and running hybrids where we must. Symmetric just needs longer keys.”
Tattoo line: Curve your enthusiasm for FUD. Grover halves; Shor breaks. Act accordingly.
— Scott G
Threat intelligence every morning — new victims, new groups, what matters, in plain English. Free, with receipts.
Subscribe to the Daily →
Scott Gardner ·