QC resistant algorithms?

Lachlan Gunn lachlan at twopif.net
Wed Dec 16 21:14:29 CET 2015

Long story short, there exist algorithms that are hypothesised tho be
QC-resistant, though as far as I know nothing is proven in that
respect.  Those that do exist, there's still a substantial possibility
that they'll be broken.  Key and signature sizes are generally large,
kilobytes to megabytes.

Certainly nothing is standardised, let alone being ready to go into OpenPGP.

This is all outside of my area, so someone please correct me if I'm way off.


