[1] http://www.open-std.org/jtc1/sc22/wg14/www/docs/n2472.pdf
6,083 karma · joined November 17, 2013
[1] http://www.open-std.org/jtc1/sc22/wg14/www/docs/n2472.pdf
On a slightly more personal note: What are some undefined behaviors that you would like to turn into defined behavior, but can't change for whatever reasons that be?
Though I don't see this recapturing the casual reverse engineering market that Ghidra ate for lunch unless they have very compelling IDA Home pricing for the decompilers as well (the “One processor family of choice from the most common processors: PC, ARM, M68K, MIPS, PPC” statement is kind of vague about that).
Probably because its authors are all big-name people and their paper says:
> We have placed TweetNaCl into the public domain, and we encourage applications to make use of it.
I kind of hope they'll also add ristretto448 since RFC 7748 and 8032 include X448/Ed448, so that the draft has feature parity (and covers the h = 4 case properly).
[1] https://mailarchive.ietf.org/arch/msg/cfrg/3RRpX9hME5ErtAzCo...
[2] https://mailarchive.ietf.org/arch/msg/cfrg/wd8pprUfJoNhvEQE0...
[3] https://mailarchive.ietf.org/arch/msg/cfrg/pT2ML68BapPAcUiSk...
Assuming you are talking about the Renes–Costello–Batina formulas, they're complete, but not necessarily efficient. According to [1], optimized short Weierstrass with the complete formulas is still 1.5 to 3 times slower than Curve25519. I imagine the numbers won't be much better for Edwards25519, either. There's definitely a ton of potential for a better complete addition formula on Weierstrass still left.
> Ristretto is nice but so terribly complex
Ristretto is nice, terribly complex, and you don't actually need to care about the conceptual complexity. As an implementer, your only job is to execute the explicit formulas in section 5 of the Ristretto website. You do not have to be able to follow the hard math (just how you do not have to be able to follow the hard math involved in making the explicit formulas). Plus the entire thing can be trivially constant-time given a constant-time selection primitive and constant-time field arithmetic. It's not that much more difficult than doing regular point compression on your own.
[1] Peter Schwabe, Daan Sprenkels. The complete cost of cofactor h=1 (published in INDOCRYPT19), https://eprint.iacr.org/2019/1166.pdf
People seem to have been experimenting with applying these restrictions from the outside, but it's generally hard to guess how a large program from ports will behave.
The C++ standards committee can standardize a backwards-incompatible "new" C++ for all I care as long as they don't call it C++.
You would be correct about that. And that sucks.
Fortunately, C2x will stop with the meme assumption that two's complement hasn't taken over the world (see draft N2479). It will not, however, specify signed integer overflow, which remains UB. :^)
I don't understand. You're saying “for the benefit of the community”, but then only speak about companies as negative examples. (1) Are companies inherently incapable of being members of the community to you? (2) Are people whose software is more liberally licensed (and may wish to incorporate parts of yours) not part of the community to you?
[1] https://virtuallyfun.com/wordpress/2018/11/26/why-bsd-os-is-...