Alright, it's official! 💰

@matthew_d_green and I bet on what will break first, ML-KEM-768 or X25519. The loser donates to a 501(c)(3) picked by the winner.

If you have an opinion on quantum computers or lattices, you can join with a side bet. Just submit a PR!

https://github.com/FiloSottile/ecc-vs-lattices-long-bet

@filippo @matthew_d_green the question is, who will survive till broken :)
@filippo @matthew_d_green still looking for a billionaire willing to bet $2³² against my one Dollar that there will not be a cryptographically relevant quantum computer by 2029.
@sophieschmieg heh, @matthew_d_green would not take my correctly-leveraged bet :P
@sophieschmieg @filippo @matthew_d_green Wait, would you bet $2³² that there will be a cryptographically-relevant quantum computer by 2029?
@espadrine @filippo @matthew_d_green no, I'm taking this bet at 2³² odds, since that is the usual margin for cryptographic systems. So I pay a dollar if it doesn't exist, but get 2³² if it does.
@filippo @matthew_d_green does key material re-use count as breaking?
@filippo @matthew_d_green side bet will GitHub be up in 2040 to prove the bet
@filippo @matthew_d_green I’d also love to see a physicist take part. This is getting really wild!