@dangoodin @ryanc @sophieschmieg That's a very simplified model, which I initially took as good myself, but it's effectively incorrect. In practice, 128 bits is enough. Not only that, but post-quantum crypto of Category 1 is defined by NIST as "as hard to break as AES-128".
https://words.filippo.io/dispatches/post-quantum-age/#128-bits-are-enough