5 questions to test your understanding
An organization argues they don't need post-quantum cryptography because large-scale quantum computers are at least 10-15 years away. What threat model are they ignoring?
NIST selected lattice-based schemes (ML-KEM, ML-DSA) as primary standards but also standardized a hash-based signature scheme (SLH-DSA/SPHINCS+). Why include both?
Shor's algorithm breaks RSA and ECDSA but does not break AES or SHA-256. Does this mean symmetric cryptography is unaffected by quantum computers?
During the PQC transition, hybrid key exchange combines a classical algorithm (like ECDH) with a PQC algorithm (like ML-KEM). Security holds if EITHER algorithm is secure.
The SIKE/SIDH isogeny-based key exchange was a NIST PQC finalist before being catastrophically broken in 2022. What lesson does this carry for the PQC transition?