Hacker News new | ask | show | jobs
by tux3 800 days ago
Not a lattice expert, so add salt to taste, but it looks like LWE in general (incluring RLWE)

But the current attack essentially wants q > n^2, so even if it is confirmed, not all LWE schemes are dead. There will certainly be people who tweak the params in response and carry on.

However, attacks only get better. And for people in FHE who are squeezed between performance problems and dangerously thin security parameters, it is a bad day if confirmed. There's no credible practical alternative to LWE for FHE...