3 ms·
> To start with: this isn't a paper "by a master student at ETH"; it's a research paper by Kien Tuong Truong and Matteo Scarlata, both grad students at ETH Appl
by dbrgn 4y ago
> To start with: this isn't a paper "by a master student at ETH"; it's a research paper by Kien Tuong Truong and Matteo Scarlata, both grad students at ETH Applied Cryptography, and Kenny Paterson, who is one of the best known academic cryptographers on the Internet.
That was actually a misunderstanding. Because the paper was listed at https://appliedcrypto.ethz.ch/education/student-projects/master-theses.html https://appliedcrypto.ethz.ch/education/student-projects/mas... (under the heading "Master Theses") I was under the impression that this paper was Kien's master thesis.
This misunderstanding has been cleared up thanks to an e-mail from Matteo / Kenny (it's a separate research paper that is _based_ on the thesis) and I just fixed the wording in the blogpost by using terminology "research team" and "research paper". There was no intent to misrepresent the authorship of the paper, I apologize.
> Threema insists on spelling out all the reasons these attacks are difficult to carry out in practice. Who cares?
A lot of people who used or use Threema do care. I fully understand your argument from an academic standpoint. But if there's a website accopmanying the paper that summarizes the attacks in simplified terms, then I assume that the target group of that website are non-academics (otherwise folks could simply read the paper), and then the risk analysis / impact is an important aspect.
> Everybody, most especially Threema, should be going out of their way to extract lessons from research like this
I can ensure you that we do :) (Including lessons on communication.)