https://nitter.net/hashbreaker?lang=en
For FIPS in particular, they've first gotta sunset the traditional algorithms for anyone to strictly need to care (and even then, parallel constructions of PQC+traditional could let other PQC algorithms in -- like the Chrome experiments -- from a FIPS perspective, you can treat the PQC like plaintext). And for them to be useful, adoption needs to occur in the IETF communities (PKIX, TLS, SSH, IKE, ...).
You're probably looking at least 5 years on the adoption window to customers running the lastest updates. NIST's blessing might help some of the IETF conversations that now need to happen. But not listening to DJB, given his track record, likely will anger a subset of IETF contributors and might hinder adoption.
It'll be interesting to see if IETF takes the more conservative approach advocates by DJB or if they continue on with NIST's blessing alone. But I'm just a watcher... :-)
Edit: and for the record, FIPS never mandated Dual EC DRBG but it was still a mistake for NIST to rubber stamp.
> (IDK what the TLS (and FIPS) PQ Algo versioning plans are: 1.4, 2.0?)
Kyber, NTRU, {FIPS-140-3}?
It looks more like a frantic attempt to get a back door into crypto in response to some post-9/11 mandate from a technically ignorant Congress than evidence for the hyper-competent super-intelligent NSA of Hollywood fiction.
Congress: "Backdoor crypto but don't tell anyone!"
NSA: "Won't work. Cryptographers will notice."
Congress: "We just added it as a line item buried in a bill about regulating the crunchiness of pork rinds. It's now a legal mandate."
NSA: "Okay, but people are gonna notice because math is math."
Congress: "Here's a billion dollars. Now go make a different math. Call it freedom math."
The rest of NIST's portfolio looks relatively sane. AES, SHA2, and SHA3 have received years and years of heavy duty cryptanalysis and have enormous implicit "bug bounties" on them by virtue of what one could steal if they could be effectively attacked. The NIST ECC curves are a frequent target of speculation about being backdoored but I've seen several cryptographers argue that if they are it means we really shouldn't use ECC at all. It would mean the NSA knows something very significant about ECC that is still after all these years (the NIST curves are two decades old) far beyond what the academic community knows.
Are there better things today outside NIST? To some extent. ARX ciphers and hashes have become immensely popular. They have the really nice properties of being efficient without special hardware (unlike AES) and being fairly side channel resistant. AES is still massively faster (2-4X) with hardware support though. In terms of cryptographic strength ChaCha has some theoretical advantages due to the wide (512-bit) state vector but neither AES nor ChaCha have anything that even smells like a practical attack against common (correct) use cases. In practice they're probably about the same.
Unless your cryptographic design is just broken or unless you are using a very weak cipher like single-DES or RC4, you are many many orders of magnitude more likely to be attacked via a bug in the implementation, a side channel, supply chain attacks, or some form of automated or targeted social engineering (phishing, spear phishing, social engineering, etc.). It's usually easier to con humans than break cryptography.
Edit: what the Snowden documents mostly showed is that the NSA has a huge trove of zero day exploits and that they tend to hoard them. They're sort of like a multi billion dollar state backed hacking group and most of what they do is not unlike what organized crime hacking groups do.
We also know that the NSA has relationships with industry. With so much reliance on cloud services and man-in-the-middle CDNs like Cloudflare the obvious way to compromise stuff would be to directly tap systems where they are not encrypted at all. You might have Wireguard with extra hipster super cryptography but who cares if the NSA can download everything from "your" cloud or push malware to your machine via any one of the dozens of package managers you implicitly trust?