4 ms·
Thanks for pointing this out. He has his own set of candidate submissions to the NIST post quantum competition, so throwing shade at other candidates makes a bi
by bem94 7y ago
Thanks for pointing this out. He has his own set of candidate submissions to the NIST post quantum competition, so throwing shade at other candidates makes a bit more sense now.
I've done some analysis on one of his candidates and it was by far the slowest on cores which do not feature wide vector operations. My opinion is that you shouldn't just optimise for Intel (as many submissions do) for all the obvious reasons.
Edit:
A quote from the slides by Nigel Smart which Bernstein criticises - "[We] Would caution NIST against putting too much emphasis on academic measures of performance of algorithms for this reason"
- I couldn't agree more.
- nemo1618 7y agoSIMD is available on more than just Intel. What platforms did you test on?
- bem94 7y agoIndeed. I was actually looking at very small / embedded cores which do lack SIMD. Think ARM M0/M3/RISC-V-IMC.
- zaarn 7y agoI think it's fair to optimize for CPUs that have vector operations, though optimizing for Intel specifically is unfair, so much I agree with you.