Hacker News new | ask | show | jobs
by sterlind 1438 days ago
from skimming it, his main argument is that Kyber relies on many constructions (e.g. cyclotomic polynomials) that are actively under attack - researchers have been successfully chipping away at them and show no signs of stopping.

he also alleges that NIST have been moving the goal posts to favor Kyber, and they've been duplicitous in their narrative.

he favors NTRU, which iirc isn't his.

3 comments

Cyclotomic polynomials are incredibly standard in the field. The only researcher I know of who has issues with them is DJB, and there has not been significant advances in cryptanalysis due to usage of cyclotomics (with the exception of problems not used by NIST candidates, meaning the whole SOLIQUAY thing)
NTRU also relies on cyclotomic rings, so if distrust in cyclotomics was a good reason to reject Kyber, it would apply to NTRU too.
My understanding is that he worked on NTRU Prime, which would have somehow benefited from NTRU being choosen.