Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
mswphd
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
12 ms
·
121.
▲
by
mswphd
4mo ago
there is no even conjectured candidate for a backdoor in the standardized PQ schemes. This is different from other backdoors in the past, for example 1. for DUAL_EC_DRBG, the fact that it could hold a backdoor was understood quite early o
122.
▲
by
mswphd
4mo ago
worth clarifying that you're both right that this is often referred to as a "hybrid", and there is the exceedingly unfortunate naming collision that "Hybrid Encryption" can also mean something separate, namely using
123.
▲
by
mswphd
4mo ago
it arguably still is. The primary unit of production of the jobs of mathematicians is itself not particularly useful for society. In this sense funding them is a jobs program. It is also true that they occasionally produce things of great
124.
▲
by
mswphd
4mo ago
not everyone responds to a perceived social ill by thinking "maybe I should gamble"
125.
▲
by
mswphd
4mo ago
They are, my point is that this only became obvious later. The initial NTRU preprint frames it as a scheme based on modular polynomial arithmetic, rather than anything related to lattices. At the end of section 4 they even explicitly descri
126.
▲
by
mswphd
4mo ago
Yes I know. That was what my initial paragraph was about. And yes, our formal understanding of LWE is much better than the original NTRU problem. NTRU itself 1. admits non-trivial attacks if the ciphertext modulus is too large, as well as 2
127.
▲
by
mswphd
4mo ago
for mathematicians, they do a form of fundamental research that is 1. (generally) incredibly cheap to fund, and 2. (occasionally) has extremely out-sized commercial impacts. This is to say that jobs programs for math (and more generally fun
128.
▲
by
mswphd
4mo ago
I'm generally sympathetic to your point, it is just difficult for this particular topic. For example, I mentioned how precision in cryptographic language is important, as there was a discussion about combiners for encryption, when real
129.
▲
by
mswphd
4mo ago
With the caveat (for other commenters) that "lattices" means several things that were not viewed with a unified lens in the 90s and 2000s, the main lattice scheme of interest now (LWE) actually was introduced in a quite literal se
130.
▲
by
mswphd
4mo ago
both encrypting in parallel and encrypting in the second way you mentioned are bad ideas, and are far from being what is seriously being discussed when people talk about hybrid KEMs. Encrypting in parallel is explicitly IND-CPA insecure if
131.
▲
by
mswphd
4mo ago
"Intuition" about how cryptography works is notoriously bad. Many intuitive things about cryptography are false, and many true things about cryptography are non-intuitive. For this reason it is difficult to seriously discuss crypt
132.
▲
by
mswphd
4mo ago
It's worth noting that the above assumes that grover's is optimal for symmetric crypto. There are not that many quantum attacks against symmetric crypto that are better than grover's, so in some sense this is justified. But t
133.
▲
by
mswphd
4mo ago
this is not an accurate description/heuristic of how quantum computing works. It would predict quantum computers can solve problems that they cannot solve. For a more accurate account see e.g. https://www.quantamagazine.org&
134.
▲
by
mswphd
4mo ago
you can sort-of view it that way, but it's not particularly useful. There are settings where you can view (steps of) a cryptographic algorithm as applying a one-time pad with a pseudorandom pad (say counter-mode encryption for the most
135.
▲
by
mswphd
4mo ago
It's not particularly related. We have efficient quantum algorithms for RSA and discrete logarithms. Both are solved by viewing them as instances of the "hidden subgroup problem" over an abelian group. Some well-known other p
136.
▲
by
mswphd
4mo ago
Primality testing was essentially solved in the 70s with Miller-Rabin. AKS made that (randomized) algorithm deterministic, albeit at much higher (polynomial) running-time. For your overall question, the current record-holders for integer fa
137.
▲
by
mswphd
4mo ago
Worth mentioning the lattice KEM he backed (NTRU prime) is part of a class of lattice-based assumptions that admitted devastating attacks (though not in the parameter regime relevant to public-key cryptography applications). By this I mean
138.
▲
by
mswphd
4mo ago
The controversy lately isn’t for encryption. We have a fine hybrid KEM, and it’s being standardized/deployed most places. The issue instead is for signatures. We don’t have a fine hybrid signature. Concretely, our current hybrid signat
139.
▲
by
mswphd
4mo ago
seems like it could be a decent opportunity for a bad actor to slip in something nefarious as well. We all know that nobody is reviewing a >>500k loc diff. For something like the Bun rewrite, where plausibly the person driving the age
140.
▲
by
mswphd
4mo ago
they're using c2rust. It transpiles c -> rust "directly", e.g. ints map to libc::c_int, pointers map to pointers, array access map to dereferencing pointers at an offset, etc. Typically the suggested way to use it is to ob
141.
▲
by
mswphd
4mo ago
Looking at LLMs applications to math might be instructive. A year ago when they had some preliminary claims/results, people would hypothesize they had the answer implicit in their training data (and so were being "better search&qu
142.
▲
by
mswphd
4mo ago
posted as a sibling to your comment, but you'd likely be interested in https://scottjg.com/posts/2026-05-05-egpu-mac-gaming/
143.
▲
by
mswphd
4mo ago
people have gotten this to work (for a sufficiently sketchy definition of work) for linux run in QEMU at least. https://scottjg.com/posts/2026-05-05-egpu-mac-gaming/ in particular, the conclusion of that article i
144.
▲
by
mswphd
4mo ago
even a max size context window is what, ~1M? iirc tokens are generally part of a vocab of size ~300k. Assume no compression before the encryption (no clue if this is true, but compressing text before encryption can leak info regarding the m
145.
▲
by
mswphd
4mo ago
worth clarifying "chat" is actually (linguistically) completely separate from a shorthand for ChatGPT. Livestreamers (e.g. on twitch/youtube) often talk to "chat", the people watching. Visually, they're just na
146.
▲
by
mswphd
4mo ago
The math was linked in the article https://arxiv.org/pdf/1908.04251
147.
▲
by
mswphd
4mo ago
they do get attention, but generally people don't dwell on how unpredictable they were. Operation Warp Speed got covid vaccines out within ~1 year. Initial predictions were more in the >= 5 years time range. Fast covid vaccines were
148.
▲
by
mswphd
4mo ago
LLMs do significantly better when they get reliable feedback on their actions (try to create any non-trivial project in some language without letting the LLM use a compiler. Similarly, talking with a "chat LLM" will produce worse
149.
▲
by
mswphd
4mo ago
you can try doing `cargo build --timings ...`. It will generate a report of how long each crate takes to compile etc. It sounds like you know that your final crate is the culprit, but this would let you confirm it. If you suspect the issue
150.
▲
by
mswphd
4mo ago
sure, but high-quality harnesses require less gpu compute/VRAM, and plausibly can be used locally by most users.
More ›