Quantum resistance

The Cardano roadmap emphasises quantum resistant signatures:

As I understand the Ouroboros consensus foundations (namely, the RNG) uses non-quantum secure crypto. Indeed, the SCRAPE paper provides two constructions, one based on DDH and the other on pairings, both of which break under quantum computers.

Why develop quantum-secure signatures if the consensus layer would break with quantum computers?

I think they will work on it in the future, as the whole protocol must be quantum resistant.

DDH is just an assumption which holds for some certain groups, and they use it because it can prove that the PVSS is provably secure. But, PVSS can be easily lifted up to QROM by replacing the DDH with some supersingular elliptic curve (SEC) based algorithm.

