Here's the warning: Lattice-based cryptography is much more risky than commonly acknowledged. This applies, in particular, to lattice KEMs under consideration within the NIST Post-Quantum Cryptography Standardization Project (NISTPQC) as of October 2021. The above document...
Yes, many. I believe he's on the SPHINCS+ team (was standardized), Classic McCliece (round 3, not standardized), and NTRU_PRIME (round 3, passed over for Kyber). Perhaps more, but he has significant skin in the game.
from skimming it, his main argument is that Kyber relies on many constructions (e.g. cyclotomic polynomials) that are actively under attack - researchers have been successfully chipping away at them and show no signs of stopping.
he also alleges that NIST have been moving the goal posts to favor Kyber, and they've been duplicitous in their narrative.
code_biologist|3 years ago
There's a linked PDF paper with more detail.
mixedmath|3 years ago
Retr0id|3 years ago
kzrdude|3 years ago
markschultz|3 years ago
bawolff|3 years ago
api|3 years ago
forty|3 years ago
sterlind|3 years ago
he also alleges that NIST have been moving the goal posts to favor Kyber, and they've been duplicitous in their narrative.
he favors NTRU, which iirc isn't his.
0des|3 years ago
unknown|3 years ago
[deleted]