Why is McEleice Cryptosystem not used or endorsed?

McEliece Cryptosystem looks solid, has faster encryption and decryption time and more secure than RSA, and is not decodable by Shor’s Algorithm making it secure against quantum attacks and have been since the 70s. I am curious as to why it’s almost obsolete and used by no-one despite being quite secure than RSA and Diffie-Hellman.

I believe it is because it is not standardized yet, but it is in NIST’s standardization candidate list so if all goes well, we should see it in 2023-24 being rolled out/used.

2 Likes