> NSA, by the way, rescued DES from differential cryptography, the core mechanism by which block ciphers and hash functions have been attacked ever since
That's why you use ML-KEM 1024 at all... As part of a hybrid.
There is no public reason to think that 1024 is better than 768, or DJB's S-NTRU-P 761. The NSA might know something, but we can't trust them. So, use a hybrid, in case they are really just trying to protect us.
That can't be the argument --- it can't be that NSA simply knows a vulnerability that impacts one very specific lattice scheme and not the others. The reason for that is a cryptographic concept known as the Vizzini Conjecture: the argument you just put forward can be applied to literally any cryptographic standard NIST authors. Since NSA knows that, and knows you know it, you can clearly not choose the wine in front of you. It must be that the standard NIST picks is the only secure one, so that NSA can see it tainted by NIST association.
But yes, this is the useful conversation to have. There are other scenarios! You can get into more detail on where MLKEM came from, for instance.
Yes, they trick me and I pick the poisoned wine... But wait, no, I used a hybrid. Imagine the code can't be backdoored (it's proven not to crash/be slow/be exploitable) so at worst it can make the security no better. At best, the NSA knows a whole new subfield of cryptography (from history: differential cryptanalysis) and it really is more secure.
They laugh at us while we try to think of how 1024 is better than 768: "bigger is better, right?" "does 1024 refer to the number of years it takes Nightmare Moon to break the code?"
There is nobody at IETF saying you shouldn't use a hybrid! In fact, it's the exact opposite: hybrid ECDH/MLKEM is a standards-track RFC, and the proposed pure-MLKEM RFC is not, nor is it "Recommended" (in IETF parlance).
Let's keep the thread coherent: the original claim, by cryptographer 'cassonmars, is that the issue here is NSA pushing bad standards. It's not "hybrid vs. pure", which is a non-issue. All I asked for was a plausible story about how NSA might have pushed a bad PQC standard.
> Let's keep the thread coherent: the original claim
How do you save your poisoned wine? A hybrid with 1024 is made less trustworthy if the NSA pushes 1024 alone, since then we know that they want customers to use 1024 alone, which is what they would want if it was weak. But they know that we would know that, so if they really want to help us they should withdraw the draft. If it was strong but we know why, they shouldn't want to make us doubt ourselves. If it is strong (and 512 and 768 are not) they can't tell us, and can only subtly point to their own double encryption and security level documents. The only move that can cover all the cases is a hybrid with 1024, so this draft is a bad standard.
Sadly the line of research seems to have been abandoned. Kind of understandable with the ascent of LLMs: there is no time left for a multi-decade research program.
Retirement accounts have to passively invest, but not in S&P500 specifically I think. I'm sure there will be passive funds that don't adapt the rules change.
edit: Google informs me that you can change the stock allocation in your 401k at any time.
Oh, I wasn't sure if you were referring to the X link in the original post.
Yeah I don't know what's going on, they banned me for being a spambot or something. Then they unbanned me again, I got the email, but the site hasn't caught on it seems. If it's still banned in a few days I'm gonna remind them about the DSA again. Technical issues are not an excuse to get out from legal obligations.
No the cartoon character. It's part of an awful series of AI jokes, maybe don't look it up. There's a (2011? "new") show for 9 year old girls that has most of the characters female, so God (Celestia) is a woman. Or a horse really. I haven't watched it. I don't think Luna or Celestia were in the old show.
Robin Hanson thinks they should. He makes a comparison to the (public company) Morton-Thiokol trading minutes after the shuttle explosion. Insider trading (allowed on future markets) would have let that price move before the explosion.
The Hello page is very wrong. Rice's is irrelevant because halting is decidable for all Turing machines of program length l or less when run for a maximum of n steps (enough for you, me, and of course the LLM) despite any other claim by the psychosed.
Well it isn't primarily the technicality aspect but rather the same risks that apply to end users are also applied to the people working at the polling station and their equipment, bringing it up when you are talking about one side only is just a tactic to discredit it. That being said, modern phone OSes are also unlike before, app isolation among others prevent such attacks, I don't think I came across a new attack that just altered another app on the fly, otherwise, we would have hundreds of cases of people getting their bank accounts compromised. In fact, I think from a technical standpoint, the risks of having such malware on end users' devices are harder to implement compared to infecting say the Android OS running on the voting screen at the polling station, or anywhere else in the process. Because in the end users' ones you can restrict the app to run under certain criteria similar to banking ones, and independent security researchers can check it for potential vulnerabilities, meanwhile an internal app used in the polling station won't have these measures, and you can even assume the OS/packages are outdated and vulnerable, making it far less secure, something like how flock cameras Android OS is a security nightmare for example.
That's why you use ML-KEM 1024 at all... As part of a hybrid.