Source: cirosantilli/is-aes-quantum-resistant
= Is AES quantum resistant?
{tag=Quantum resistant cryptosystem}
2020-so-far yes, <Grover's algorithm> would only effectively reduce key sizes by half:
* https://crypto.stackexchange.com/questions/6712/is-aes-256-a-post-quantum-secure-cipher-or-not
* https://qvault.io/cryptography/is-aes-256-quantum-resistant/
but there isn't a mathematical proof either.