4 ms·
Kyber? For some reason I hear that and think "isn't that the PQ with a foundational Assumption(!) that's been proven trivial for binary computers to break?"
by telgareith 2y ago
Kyber? For some reason I hear that and think "isn't that the PQ with a foundational Assumption(!) that's been proven trivial for binary computers to break?"
- zinekeller 2y agoI'm not sure for Kyber, but SIKE/SIDH (another PQ candidate) does have those exact problems (https://eprint.iacr.org/2022/975.pdf https://eprint.iacr.org/2022/975.pdf)
- tptacek 2y agoCompletely unrelated algorithms; it might be hard to come up with two algorithms less related to each other than module lattices LWE and supersingular isogeny graph Diffie Hellman --- even the outcomes of the two algorithmic approaches are different (SIDH was attractive because it gives you a Diffie Hellman, and Kyber gives you a KEM). (I just want to make it clear that this isn't a lingering concern about lattice cryptography, fwiw.)
- tptacek 2y agoNo.