Hacker News new | ask | show | jobs
by matthewdgreen 2082 days ago
A general rule is that cryptographers never know what applications’ requirements are, unless we’re also developing those applications. The Ed paper took a very opinionated view on what the requirements should be: out in the real world, it turned out that they were often stronger. This doesn’t mean anyone is “wrong” per se, but it should perhaps be a lesson in humility for people who develop primitives.
2 comments

In this case, simply fixing the problem would have taken the same or less work than writing the quoted paragraph.
At least the paper was extremely clear in that particular respect, often this isn't the case.