@cthos @aud I would argue strongly that we do, that the timelines for practical RSA breaks and post-quantum crypto line up pretty well, and so forth. Considering forward secrecy for backups does complicate things substantially, though... then the question becomes whether or not *current* post-quantum cryptography will remain quantum-resistant for the lifetime of the backup. I'd again argue yes, but that's more subtle.