Dustin Moody from NIST: “you don’t need more than 128 bits of symmetric keys for post-quantum security” #rwc2026

Say it louder, for the people in the back!

@filippo Now, if they could only get their government colleagues at the NSA who wrote guidelines for large parts of that same government to agree, and ideally also convince them that SLH-DSA and SHA3 aren't the devil and hybrids are good, then we could probably start making some progress.