@filippo.abyssdomain.expert I agree to disagree: 128-bit keys MUST BE upgraded during a post-quantum migration. kerkour.com/128-bit-keys...
Are 128-bit symmetric keys really secure against quantum computers?
Quantum computers are a threat to traditional cryptography, more specifically to asymmetric cryptography (signatures and key exchanges) with Shor's algorithm enabling fast factoring of big numbers.
kerkour.com
There are no technical or compliance reasons to double the size of symmetric keys in response to the threat of quantum computers. This common misunderstanding of Grover's algorithm risks wasting limited resources that should go towards deploying actually urgent post-quantum algorithms.