b***@openmailbox.org
2017-08-19 04:11:16 UTC
If I understand correctly, DJB describes how NTRU-Prime is more robust against certain attack classes that Ring-LWE is more prone to:
https://twitter.com/hashbreaker/status/880086983057526784
***
About two months later DJB releases a streamlined version of NTRU-Prime that is faster, safer and uses less resources than the latest version of New Hope while (wait for it...) completely eliminating decryption failures !:
https://twitter.com/hashbreaker/status/898048057849380864
https://twitter.com/hashbreaker/status/898048506681860096
https://twitter.com/hashbreaker/status/898048760009420801
https://twitter.com/hashbreaker/status/898391210456489984
***
Boom headshot! AEZ is dead in the water post quantum:
Paper name: Quantum Key-Recovery on full AEZ
https://eprint.iacr.org/2017/767.pdf
https://twitter.com/hashbreaker/status/880086983057526784
***
About two months later DJB releases a streamlined version of NTRU-Prime that is faster, safer and uses less resources than the latest version of New Hope while (wait for it...) completely eliminating decryption failures !:
https://twitter.com/hashbreaker/status/898048057849380864
https://twitter.com/hashbreaker/status/898048506681860096
https://twitter.com/hashbreaker/status/898048760009420801
https://twitter.com/hashbreaker/status/898391210456489984
***
Boom headshot! AEZ is dead in the water post quantum:
Paper name: Quantum Key-Recovery on full AEZ
https://eprint.iacr.org/2017/767.pdf