Lattice-based crypto is all the rage among snakeoil marketing (right after One-Time-Pads).
Lattice-based crypto is all the rage among snakeoil marketing (right after One-Time-Pads).
And don't get your hopes up about seeing a practical implementation of iO any time soon; it's thoroughly and utterly impractical at the moment, and will remain so for the foreseeable future.
Yes, it was (is?) one of the candidates for post-quantum public-key encryption. But that doesn't stop terrible projects from claiming to have it in their marketing today.
Also, no forward secrecy.
My understanding of OTP's implies that these must be used only once. As such they offer the same PFS as all the schemes I know of. PFS does not guarantee the secrecy of a specific message. It does guarantee that if you are able to crack one message you can't use the key to crack others. Therefore if you use an OTP only once it gives you the same guarantees.