Home › Blog

I did Shor, so let’s look at Grover’s — w00t.

I did Shor, so let’s look at Grover’s — w00t.
(PQC FUD edition: why your AES isn’t spontaneously combusting)

There’s fresh fear-mongering about Grover’s algorithm “breaking AES.” Breathe. Grover is a quadratic speedup for brute force, not a magic AES disintegrator.

What Grover actually does (no vibes, some math):
Classical key search: ~2^k tries.
Grover key search: ~2^(k/2) quantum iterations if you can build a reversible AES oracle and run it fault-tolerantly zillions of times.
Translation: AES-128 ≈ 64-bit quantum security (too small for long-term secrecy). AES-256 ≈ 128-bit quantum security (still strong).

What it does not do:
It doesn’t “break” AES structure—just speeds up dumb search.
It doesn’t help without a known plaintext–ciphertext pair for the oracle.
It doesn’t affect modes or block sizes; it only targets the key.
It doesn’t run at scale today; you’d need a huge, fault-tolerant QC with AES circuits and error correction on repeat.

So what’s worth doing (and saying) right now?
Use AES-256 for data that needs a long shelf life.
For hashes, remember: Grover makes n-bit preimage ≈ 2^(n/2); plan accordingly (e.g., SHA-256 still fine).

Save your urgency for public-key: Shor is the one that kneecaps RSA/ECC. That’s why we ship PQC (Kyber/Dilithium), hybrid KEMs, and, above all, crypto-agility.

How to de-FUD a meeting in one breath:
“Grover halves effective key bits; AES-256 remains robust. Our quantum risk is mainly public-key, so we’re migrating to PQC and running hybrids where we must. Symmetric just needs longer keys.”

Tattoo line: Curve your enthusiasm for FUD. Grover halves; Shor breaks. Act accordingly.

— Scott G

#PQC#Grover#Shor#CryptoAgility#AES256#HybridKEM#SecurityArchitecture
The Probably Fine Daily

Threat intelligence every morning — new victims, new groups, what matters, in plain English. Free, with receipts.

Subscribe to the Daily →

View the original on LinkedIn ↗

← All writing