1

I read in the Q/A on this site: " https://crypto.stackexchange.com/questions/76738/has-aes-128-been-fully-broken" that AES-128 is resistant to PQC. This is true even when Grover's algorithm was used because the operations on QC are much slower and the algorithm isn't parallelizable.

What about modern hash function families like SHA-2 or SHA-3? Will SHAKE128 be vulnerable?

Maarten Bodewes
  • 96,351
  • 14
  • 169
  • 323
Molo4
  • 31
  • 1

0 Answers0