4 ms·
I believe 256 bit symmetric keys and hashes are currently recommended because it's double the classically-secure 128 bit.
by AgentME 2y ago
I believe 256 bit symmetric keys and hashes are currently recommended because it's double the classically-secure 128 bit.
- adastra22 2y agoBecause there is a different sqrt speedup concern regarding the birthday paradox / collision resistance. These combine with Grover's to get you a O(N^(1/3)) speedup when finding a collision, making a 256-bit hash have ~85 bits of security against a quantum adversary. You'd need to switch to a 384 bit hash function to keep a 128-bit security threshold. In practice, this means SHA-512.