"good enough" relies on a threat model. Cryptography researchers work in the abstract - without a threat model you must consider cases where your attacker has unlimited resources.
It's good enough for you and me, but research isn't meant to be practical, imo