A Guide to Post-Quantum Cryptography
blog.trailofbits.com
blog.trailofbits.com
An especially good focus here is the comparison of systems based on different classes of intractability assumptions.
Isogenies are a good use case for e.g. constrained hardware that doesn't have much space but can tolerate longer key exchange turnaround times. Conversely you'd really want something like lattices for typical key exchange between a client browser and web server.
Code-based solutions have similar advantages and disadvantages lattices and are much older. McEliece is only slightly older than RSA. But because the structure of most types of error correcting codes, it has been very difficult to develop safe systems with the same versatility as lattice based systems. Code-based systems have fewer intractability problems available and virtually all types of codes tried to date have been broken - see research over the past two decades by Nicolas Sendrier, for example.
https://twitter.com/durumcrustulum/status/839279075315314692
> A major problem with this system is that it has very large keys. To encrypt just one bit of information requires public keys with size n^2 in the security parameter.
Can't this be solved by e.g. forcing some kind of random sparsity structure on the matrix and then compressing with a format like CSC or CSR? (probably just not understanding LWE completely)