I read online that AES-256 is Quantum Safe , so AES-256 used in AES-GCM and AES-OCB should be quantum safe , just wondering is ChaCha20Poly1305 quantum safe , if it is then is it better than AES-256 with GCM or OCB mode?
Asked
Active
Viewed 133 times
0
-
I would argue this is essentially a duplicate of Security level of Poly1305 and GMAC and existing ChaCha20 vs AES comparisons, like XChaCha20 vs AES 128 security and speed (XChaCha20 uses ChaCha20 internally, which was discussed). – samuel-lucas6 Jul 21 '22 at 06:16
-
Also, Is XChacha20 - Poly1305 Quantum resistant?, Post-quantum authenticated encryption, Poly1305-AES vs AES-GCM, and Changing an Encryption scheme from AES to ChaCha20. The new bit is the discussion of OCB. – samuel-lucas6 Jul 21 '22 at 07:31