The point is that you can build stuff on top of RSA today even if you expect it to be broken eventually if RSA is only for identity verification.
The point is that you can build stuff on top of RSA today even if you expect it to be broken eventually if RSA is only for identity verification.
[1] https://security.stackexchange.com/questions/33069/why-is-ec...
There are several choices with scaling RSA too, you can push the primes which slows generation time considerably. Or the more reasonable approach is to settle on a prime size but use multiple of them (MP-RSA). The second approach scales indefinitely. Though it would only serve a purpose if you are determined to hedge against the accepted PQC algorithms (Kyber/MLKEM, McEliece) being broken at some point.
The Intel 4004, in 1971, had only 2,250 transistors.
A handful of qubits today might become a billion sooner than you think.