logoalt Hacker News

tptacektoday at 12:05 AM1 replyview on HN

NSA wrote Dual EC. A team of (mostly European) academic cryptographers wrote the CRYSTALS constructions. Moreover, the NOBUS mechanism in Dual EC is obvious, and it's not at all clear where you'd do anything like that in Kyber, which goes out of its way not to have the "weird constants" problem that the P-curves (which practitioners generally trust) ended up with.


Replies

cryptonectortoday at 3:18 AM

It took a couple of years to get the suspicion about Dual_EC out.

show 1 reply