| ▲ | vlovich123 an hour ago | |
They did both - they strengthened it from differential integrity but weakened it by picking a known-to-be-too-short key length. Meaning they had the compute power to crack it but others couldn’t do the same through pure algorithmic means. As for your post below > it can't be that NSA simply knows a vulnerability that impacts one very specific lattice scheme and not the others Ok. My argument is they know all lattice schemes are weak and the push to use a lattice-only scheme is precisely to have a cryptographic mechanism they can easily bypass without a classical known-secure backstop. | ||
| ▲ | tptacek an hour ago | parent [-] | |
See, here's another argument that doesn't work here, because Bernstein very publicly backs a different lattice cryptography scheme. In addition to the previously-stated reason why that argument is inoperative (besides being unfalsifiable, it admits a strategy where NSA "poisons the well" to get people to avoid a particular construction or family of algorithms, so that we all move to weaker ones --- a counterfactual that should be much more vivid after what was released this week!) | ||