@khm @ambiguous_yelp @dalias @sammi @joelanman While I agree that it's nowhere "close", the "Harvest Now, Decrypt Later" is a tangible threat -- even if they're 10 years out.
However, I wouldn't bring that up for Signal since that'd require a *lot* of Harvesting, a *lot* of cracking and we'd only get some of the data to decrypt a whole Signal interaction since only the KEX would be affected and things like PFS etc. help against a lot of simpler attacks.
This *is* a threat for, say, secret govt. documents where deciphering has a big impact even 20 yrs later and the computing requirements (given you have access to quantum computers) are comparatively acceptable.