Ok, but this also holds for possible attackers.
Ok, but this also holds for possible attackers.
This means that ARX functions will have less published analysis, but may still be successfully attacked.
This isn't even a new argument they're making here. It's been well understood that simple cipher designs are better, because they are easier to understand. If you can understand it well, yet not break it, that gives confidence. If you don't understand it, it might break as soon as you do.
* make your cipher complicated, so that analysis and attacks are hard
* make your cipher easier to analyze and attack
The second one usually brings more confidence in the strength of the algorithm after a long period of peer review and cryptanalysis.
PS: not sure but I think I remember reading that Ketje was designed specifically to make theoretical attacks and analysis easier: https://keccak.team/ketje_contest.html