News Grower

Independent coverage of AI, startups, and technology.

Ars Technica Apr 21, 2026 at 12:35 Big Tech Rising Hot

Contrary to popular superstition, AES 128 is just fine in a post-quantum world

A stubborn misconception is hampering the already hard work of quantum readiness.

Signal weather

Rising

Momentum is building quickly, so this card is a good early entry point into the topic.

By Dan Goodin Original source
Contrary to popular superstition, AES 128 is just fine in a post-quantum world

With growing focus on the existential threat quantum computing poses to some of the most crucial and widely used forms of encryption, cryptography engineer Filippo Valsorda wants to make one thing absolutely clear: Contrary to popular mythology that refuses to die, AES 128 is perfectly fine in a post-quantum world. AES 128 is the most widely used variety of the Advanced Encryption Standard, a block cipher suite formally adopted by NIST in 2001. While the specification allows 192- and 256-bit key sizes, AES 128 was widely considered to be the preferred one because it meets the sweet spot between computational resources required to use it and the security it offers. With no known vulnerabilities in its 30-year history, a brute-force attack is the only known way to break it. With 2128 or 3.4 x 1038 possible key combinations, such an attack would take about 9 billion years using the entire Bitcoin mining resources as of 2026. It boils down to parallelization Over the past decade, something interesting happened to all that public confidence. Amateur cryptographers and mathematicians twisted a series of equations known as Grover’s algorithm to declare the death of AES 128 once a cryptographically relevant quantum computer (CRQC) came into being. They said a CRQC would halve the effective strength to just 264, a small enough supply that—if true—would allow the same Bitcoin mining resources to brute force it in less than a second (the comparison is purely for illustration purposes; a CRQC almost certainly couldn’t run like clusters of Bitcoin ASICs and more importantly couldn’t parallelize the workload as the amateurs assume).Read full article Comments

Stay on the signal

Follow Contrary to popular superstition, AES 128 is just fine in a post-quantum world

Follow this story beyond a single article: new follow-ups, adjacent sources, and the evolving storyline.

We send a confirmation link first, then only meaningful digests.

Story map

Understand this topic fast

A quick entry into the story: why it matters now, who is involved, and where to go next for context.

Why it matters now

Fresh coverage with immediate momentum.
There are already 6 connected articles in the same storyline to continue from here.
The story keeps orbiting around Aes+, Ars Technica, and Contrary, so the entity pages are the fastest way to build context.
Ars Technica already has 4 follow-up stories on the same theme.

Topic constellation

Open the live map for this story

See which entities, story threads, sources, and follow-up articles shape this story right now.

Click nodes to continue

Entity Cluster Article Hub Source

Story timeline

Continue with this story

A short sequence of events and follow-up stories to understand the arc quickly.

Apr 21, 2026 at 15:01 Ars Technica

CATL's new LFP battery can charge from 10 to 98% in less than 7 minutes

The self-heating Shenxing battery still performs even in Arctic temperatures.

Apr 21, 2026 at 14:45 Ars Technica

AMD Ryzen 9 9950X3D2 Dual Edition review: Tons of cache for tons of dollars

There are some practical benefits to this $899 chip, but not many.

Apr 21, 2026 at 14:24 Ars Technica

What's the deal with spacesuits for the Moon? Will they be ready in time?

NASA is down to a single provider for a critical link in its lunar architecture.

Apr 21, 2026 at 14:23 Ars Technica

Loneliness in older adults can often lead to memory impairment

A longitudinal study finds links to lapses in immediate and delayed recall.

Apr 21, 2026 at 12:35 Ars Technica

Contrary to popular superstition, AES 128 is just fine in a post-quantum world

A stubborn misconception is hampering the already hard work of quantum readiness.

Apr 21, 2026 at 02:27 Ars Technica

Pentagon pulls the plug on one of the military's most troubled space programs

Problems with the ground system would have "put current GPS military and civilian capabilities at risk."

How reliable this looks

Signal and trust for Ars Technica

This source works at a rapid pace: 100% of recent stories land in the hot window, and 0% carry visible search signal.

Trusted

Reliability

92

Freshness

100

Sources in storyline

1

Related articles

More stories that share tags, source, or category context.

More from Ars Technica

Fresh reporting and follow-up coverage from the same newsroom.

Open source page