A counter-point that perhaps everyone is taking PQ a bit too seriously [1].<p>Personally, it seems reasonable to at least spend some effort preparing for it, given the rather long lead time required to develop, study and stress the constructions needed. It might be a long time (if ever) before cryptographically relevant quantum computers show up, but if they do, we'll be glad we had a decade or two to get ready. The alternative of scrambling at the last minute while everything gets cracked seems unenviable.<p>[1] <a href="https://www.cs.auckland.ac.nz/~pgut001/pubs/heffalump_crypto.pdf" rel="nofollow">https://www.cs.auckland.ac.nz/~pgut001/pubs/heffalump_crypto...</a>