But maybe this is actually the reason behind the presentation: he sees this vast effort to transition to PQC, and he's wandering whether it is worth it or not.
And for what is worth, I'm also a bit skeptic of the maturity of PQ cryptosystem, as they tend to be much more complicated than the classical counterpart and didn't receive as much scrutiny. What happened to Rainbow (layered UOV) is a cautionary tale.
Yes, but that is why I say that his argument is moot. It is probably not worth going to PQC, and it will probably expose us to problems. But it is too late to try and get people to understand, agree on this.
The world has decided that the percieved risk makes it worth going to PQC and we can't change that fact no matter the nice pictures of Schwerer Gustav. We are in full transition mode and will not go back. Even if CRQC never materialize.
We probably will experience a number of issues, problems that we wouldn't have by not going to PQC. Driving costs, making things vulnerable. More work for us I guess.