I'm sure others already asked: "y u no sha3?" on the git dev lists. Assuming quantum computers with many qubits land, aren't prime factorization, EC and matrix math crypto basically DOA?
They just factored RSA-230, which was labelled to need 17 core years. https://news.ycombinator.com/item?id=17825383