123 karma · joined September 1, 2019
Replacing thought and curation with repeated automation is tech debt, pushed down to fundamental knowledge and understanding.
If that "bait" caused you to stop reading despite the fact that you probably agree with the author's sentiment, it's not very good bait.
That's all I can think of, though.
I could not follow where the leaf_hash is used carefully enough to figure out exactly how dangerous this is in the broader context and taking future evolution into account. But it's clearly safe as it is used now because all expected inputs have the same length.
> Note: Update on April 18: Step 9 of the algorithm contains a bug, which I don’t know how to fix. See Section 3.5.9 (Page 37) for details. I sincerely thank Hongxun Wu and (independently) Thomas Vidick for finding the bug today. Now the claim of showing a polynomial time quantum algorithm for solving LWE with polynomial modulus-noise ratios does not hold. I leave the rest of the paper as it is (added a clarification of an operation in Step 8) as a hope that ideas like Complex Gaussian and windowed QFT may find other applications in quantum computation, or tackle LWE in other ways.
Which claim do you disagree with? The claim that the trend I describe exists, or the fact that it is bad?
Note that what you describe is what I advocate: you explain that the question exists and hasn't been answered. This is not an argument that is based on the volume of work that exists.
It is also an argument you cannot (as an author) be trusted to make. Even if you cite everything that has been published that is tangentially related to your claimed contribution, there is no way a reviewer will know all of it, and no way a reviewer will be able to go and read all of it. So they can't determine whether your claim of novelty is correct unless they already know the entire field. The only defense against this is to encourage crisp and clear descriptions of claimed contributions (to knowledge or practice) and violently reject any overinflated claims. It is not to include an entire survey paper in the introduction of every piece of work that pushes the state of the art forward.
It does mean that the average paper is less accessible to the non-expert. It also encourages the regular publication of surveys whose role is solely to critically and exhaustively compare recent advances, and of textbooks whose role is to describe historic developments and their context. This is not something every paper should be doing.
I would in fact argue that the trend, in "applied" fields, of justifying the importance of a piece of work by pointing out that a lot of people are doing similar work is in fact self-fulfilling. That makes it somewhat useless as a measure of importance.
Scientific context should be critical, not just descriptive.
Because you choose to give your children freedom to operate their device however they see fit, you are in support of legislation that restricts what they can use their device to access on the internet?
There are no issues with arXiv generating the HTML and sending that over: they control the generation process, and users who visit arXiv already trust it to not be malicious. The issue is with letting the user upload their own and having it sent on to other users as is.
Neither is correct, in that neither gives the actual objective truth. Both are correct, in that they both give you estimates that can only be incorrect if they give a zero probability to the actual objective truth.
Even statistically, assume the true value is 0. Is "2 ±5" or "1 ±7" the better estimate? Assume the methods used to derive them consistently yield similar estimates. Which one is the correct method?
In mature industries, there absolutely are plenty of regulations in place to make sure that builders don't make responders' life harder. That doesn't mean that the responders aren't needed, but the fact that the software industry as a whole decided to go all "response is the only thing we need for most things" is evidence that it is not mature.
Sure, I agree with this. But then the advantage of AEAD over a bespoke EtM is not that AEAD allows the authentication of unencrypted context.
>> In fact, you must ensure that the nonce, a piece of unencrypted context, is authenticated.
> For CBC mode, sure. For CTR mode? Not really.
If you don't, you do not get ciphertext integrity: decryption will succeed, but mostly yield gibberish, if the adversary changes the nonce in a decryption query. This may expose a padding oracle, with all the nice attacks those things allow, depending on details of the application.
>> Nothing stops you from throwing more stuff in there.
> What prevents an attacker from shifting bits from the ciphertext field into the AAD field in the decrypt path and yield the same HMAC tag? Unless you have an answer to this question, vanilla "encrypt then MAC" is not sufficient. You need a better-engineered construction than that.
Yes, you need a well-engineered construction.
> Please let me know if something wasn't clear, or you feel it was missing.
And yes, your linked post covers all this, but that is not the point: your summary of the linked post just claims superiority of AEAD (which I took as integrated AEAD modes) over EtM because of a functionality you claim is missing from the latter. But in the same way you need a well-engineered integrated AEAD to get any kind of security, you will need a well-engineered Encrypt-then-MAC-with-AD construction to get a secure construction. And here "well-engineered" means "ensure unambiguous parsing of decryption inputs," we're not talking about high-flying stuff that doesn't have standard solutions.
In short: I accept the point of your linked post, and I agree with it. But I reject the claim that a functionality mismatch is what makes integrated AEAD better than a constructed EtM.