logoalt Hacker News

tptacektoday at 3:47 AM1 replyview on HN

I feel like what's most likely happening here, given your initial argument, is that you just learned that this is a debate about whether it should be forbidden to even document a particular MLKEM configuration, and you're now working backwards to the proposition that Bernstein is right.

To that I will only add that lattice cryptography is of approximately the same vintage as elliptic curve (both started in the late 1990s) and MLKEM is past the level of maturity relative to lattices that 25519 was relative to the original P-curves. (Correct me where I'm wrong here --- this is off the top of my head). This isn't "the first generation" of anything.

Just another nuance I think Bernstein is counting on you, the real audience for these posts, not having any intuition for.


Replies

directorontoday at 3:56 AM

That's a weak ad hominem deflection. Readers be the judge.

show 1 reply