How âpost-quantumâ is Kyber-1024, really?
Kyber-1024 (ML-KEM-1024) targets ~256-bit security â comparable to brute-forcing AES-256. Even if you give an attacker:
⢠a classical exascale supercomputer (10š⸠ops/s), or
⢠a massive future quantum computer running Groverâs algorithm at 10²š iterations/s,
the time to brute-force a single Kyber-1024 key is still on the order of 10šâ°â10âľÂ˛ years.
In practice, thatâs far beyond the age of the universe.
Thatâs why migrating to NISTâs ML-KEM (Kyber) family is such a critical step for long-term confidentiality in a quantum world.
