Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
mswphd
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
11 ms
·
31.
▲
by
mswphd
2mo ago
misspoke, meant rim brake bike
32.
▲
by
mswphd
2mo ago
only real worry I'd have is a scenario like 1. someone has a cheap disc brake bike for pleasure rides (mostly in the sun) 2. they get something like this for commuting or whatever 3. now they're on their disc brake bike most days
33.
▲
by
mswphd
2mo ago
it's also likely mildly more dangerous than a standard ebike, as ebikes typically overprovision their brakes. A customer putting this on a standard bike (especially a disc brake bike) might have less stopping power than they want on an
34.
▲
by
mswphd
2mo ago
ASUS does make power banks, and the vast majority of the cost of any ebike is in the battery.
35.
▲
by
mswphd
2mo ago
only temporarily, and only for multiplication. At a very high level, the idea is that you view C := [A, b] as satisfying CS = 2^8 m + e here, S = [-s, 1] is a padded version of the initial secret. So recast everything as a linear equation (
36.
▲
by
mswphd
2mo ago
the basic encryption scheme used here is fairly straightforward actually, at least the symmetric encryption version. Let s be a uniformly random, 512-dimensional u32 vector. To encrypt a message m (say a 512-dimensional bit vector for simpl
37.
▲
by
mswphd
2mo ago
conceptually your example is fine/good, but it's worth clarifying that the scheme you describe is insecure, as unpadded RSA fails to be IND-CPA secure. this is because Enc(m) Enc(m') = Enc(m m') is a predicate a passive
38.
▲
by
mswphd
2mo ago
SOTA for SVP is BDGL16. You can find discussion of it in many places, see for example https://eprint.iacr.org/2022/922.pdf it's hard to precisely analyze BDGL16, but to leading order it takes ~ (3/2)^n time,
39.
▲
by
mswphd
2mo ago
that's the running time of the BDGL16 sieve. see the intro of e.g. https://eprint.iacr.org/2022/922.pdf for some history
40.
▲
by
mswphd
2mo ago
the server doesn't do what you say. Roughly, the server has a fixed circuit C they run on the ciphertext. They run this same circuit on any ciphertext. They give you back the result. the fact that the result, when decrypted, gives the
41.
▲
by
mswphd
2mo ago
note that this is even true for an honest server. Roughly, FHE computations often require certain bounds on the (encrypted) messages for things like tuning polynomial approximation domains etc. If your messages are out of distribution for t
42.
▲
by
mswphd
2mo ago
addition is easy/essentially the same cost as standard (not really, because you have to compute mod p addition rather than mod 2^32, but ignoroing that it's roughly the same). as a general rule multiplication is the difficult part
43.
▲
by
mswphd
2mo ago
I've found having draconian phone blocking rules helps. I use Jomo https://jomo.so but I'm sure there are other competing products. Roughly, you can classify apps in your phone to things that 1. are fundamentally fine
44.
▲
by
mswphd
2mo ago
OpenRouter is (roughly) a single proxy between you + many different models + providers. it works with opencode (+ many other products), and is relatively convenient for trying out a bunch of models. for example, they already have qwen3.8-ma
45.
▲
by
mswphd
2mo ago
not really. The hardness of SVP is relevant, but this is a paper giving improved provable bounds for SVP algorithms. heuristically (which people use to choose parameter sizes etc) people assume SVP is much easier to solve, closer to 2^{.2
46.
▲
by
mswphd
2mo ago
it's worth mentioning the infinite number of decimal places isn't an issue. there is the formalism of computable numbers to get around this https://en.wikipedia.org/wiki/Computable_number roughly represent ea
47.
▲
by
mswphd
3mo ago
it doesn't overturn much. For example, here is a post from 2004 https://www.math.columbia.edu/~woit/wordpress/?p=105 it is about a purported (though incorrect) positive proof of the Jacobian conjecture in 2 d
48.
▲
by
mswphd
3mo ago
verification also requires computing the jacobian. an undergraduate-level exercise, but harder than verifying p(pt1) == p(pt2).
49.
▲
by
mswphd
3mo ago
this is only true in the IND-CPA model for most "practical" FHE work. So a more precise way to describe things is "a server who faithfully performs the task given to them does not gain any sort of insight" (perhaps with
50.
▲
by
mswphd
3mo ago
https://paseo.sh/ supports self-hosting, though I've only used it a mild amount tbh.
51.
▲
by
mswphd
3mo ago
I don't think quibbling over "equivalence" vs "equality" is useful personally. They're both "equality". Just what the sign "=" means differs depending on the type information. E.g x: ZmodN =
52.
▲
by
mswphd
3mo ago
there's been some forward movement on doing this via an appropriate intrinsic in LLVM https://github.com/llvm/llvm-project/pull/166702 note that this isn't the only "trick" needed for cons
53.
▲
by
mswphd
3mo ago
that has some technical limitations. For example, their impl can compile to wasm, which makes giving an online interpreter simpler/lighter weight than relying on running python in the browser.
54.
▲
by
mswphd
3mo ago
note that similar concepts appear in mathematics. Generally the term for it is a "mollified" function. applied to the step function, you would get a smooth cutoff function https://en.wikipedia.org/wiki/Mollifi
55.
▲
by
mswphd
3mo ago
as a heads up, there is another attack paper against McEliece today https://eprint.iacr.org/2026/1339 Note that this is by someone from the BSI. It's worth mentioning the BSI is very familiar with lattice-based sc
56.
▲
by
mswphd
3mo ago
you'd probably call it "Product NTRU" then, and be a minimum a decade out of date. So you'd probably have to do all that weird shit with co-different ideals Peikert was trying to get us all to do (I know it was "rig
57.
▲
by
mswphd
3mo ago
huh. I really wouldn't want the Nobel Prize committee in medicine doing cryptographic work then. good thing your comment has nothing to do with cryptography then :)
58.
▲
by
mswphd
3mo ago
it's worth clarifying that its entrants were all qualified, and 2 other essentially identical schemes, namely New Hope and Saber, made it very deep into the NIST competition. All 3 (roughly) took the approach of 1. take the obvious bes
59.
▲
by
mswphd
3mo ago
It really depends on what the precise details of the attack look like. 1. algebraic structure: sure use frodoKEM 2. error rates smaller than those required for worst-case to average-case reductions: idk bump error rates 3. some coding theor
60.
▲
by
mswphd
3mo ago
that's really not possible for ML-KEM. They took a well-known "boring" design, and tweaked certain internal sub-components of it. Their tweaks were good, and their analysis/exposition of it were good. So they deserve to
More ›