@freemo I actually like ECC best for efficiency, but it has 256 bit keys, and IBM projects having 128 qubit quantum this year and 256 qubits Real Soon Now. As I understand it, there are quantum algorithms that can quickly crack ECC with 256 qubits.
At that point, 4096 RSA looks real good despite the relative inefficiency. It may be the first to have a quantum algorithm to crack it - but difficulty of coordinating more qubits grows much faster than difficulty of doubling RSA key size.
@customdesigned Despite haing a 433 qubit computer breaking crypto is still years off. Valid concern though because no one wants their encrytpted data exposed even if it is years down the line.