HNHacker News
TopNewBestAskShowJobs

mswphd

405 karma · joined April 7, 2026

submissionscomments
mswphd··on NSA tries to weaken mlkem standardisation?
you're talking about what is known as NISQ quantum computers, namely quantum computers before they can do full error correction. There are no claimed cryptanalytic benefits for NISQ machines. The main claims I've seen are for quantum chemistry simulation, but even those I've heard are not too credible.

Even dedicated single-algorithm quantum computers aren't magic. Given a dedicated single-algorithm quantum computer for attacking ML-KEM, the best current cost estimate we have for it is undoubtedly slower than the classical attack. Attacking ML-KEM quantumly is thought to take exponential (quantum) time. this is (clearly) not the case for ECC.

mswphd··on NSA tries to weaken mlkem standardisation?
That document is nonsense? The current RFC is not to say

> use pure ML-KEM > hybrid ML-KEM.

the current document is instead to say

> If you are in a setting where you REALLY want to use pure ML-KEM (though we explicitly recommend you do not do it), this is the standard you would implement against.

It is also technically inaccurate. The whole argument hinges on it being negligible cost in all environments to do hybrids. This is explicitly false. See this message on the TLS-WG on explicitly this point

https://mailarchive.ietf.org/arch/msg/tls/_9i3uIVDQ3pDRswpm9...

A large list of pros/cons detailing a question that isn't being debated that is technically inaccurate is what I would expect from an LLM, not from a competent cryptographer. I am unsurprised to see it from DJB given his behavior in the last decade regarding PQC.

mswphd··on NSA tries to weaken mlkem standardisation?
DJB wrote this article after asking people to brigadge the current TLS-WG's attempt to get rough consensus on a current draft RFC for pure ML-KEM. This is clearly part of this tirade for that.

ML-KEM is not new. It's hardness is based on MLWE. LWE (a slightly harder problem) has been around for 20 years. Attacks against it stablized to be 2^{cn} time maybe 15 years ago. The value of c has been stable for nearly 10 years.

MLWE is mildly different, but still from > 1 decade ago. The only improved attacks are ~8x faster (and they are relatively naive). It has been a very popular cryptanalytic target since it was suggested (LWE has been dominating cryptography for the last >10 years).

It does not add negligible cost in all settings. In hardware, a hybrid scheme requires an implementation of SHA2 and SHA3. This is expensive.

Any good design must not do fine when even the worst happens. When we did the AES competition, we did not combine AES with DES (or 3DES) in case AES was weak.

This is beside the point though. Most cryptographers would still recommend the hybrid over pure ML-KEM. This RFC (for pure MLKEM) is marked "recommended to implement = N". It is purely for settings where the implementors independently want to use pure ML-KEM for some reason. In these settings, they should implement it against some standard, so it is interoperable.

mswphd··on NSA tries to weaken mlkem standardisation?
it is easy to point to ghosts in the corner. Random fearmongering is not a technical argument though. There have been no technical arguments to justify the random fearmongering. Pointing to prior behavior in a way that is inconsistent with the current situation is especially annoying fearmongering.
mswphd··on NSA tries to weaken mlkem standardisation?
SIKE is a completely different scheme based on completely different hardness assumptions from a completely different area of math. It is just as sensible to call elliptic curve cryptography to be a predecessor to ML-KEM. Nobody would do that.

The hardness assumption from ML-KEM is from 2005 (in teh algebraically unstructured case. The biggest speedup known due to algebraic structure is ~3 bits, e.g. 8x speed improvement). It has taken exponential time to attack since then. Instantiating a standard ~20 years after introduction is slower than what we did with RSA, or with elliptic curve cryptography.

Therea re settings where hybrids are not free, for example hardware. The standard hybrid suggestion (XWING) would require hardawre to implement both SHA2 and SHA3. See this recent TLS WG post detailing this

https://mailarchive.ietf.org/arch/msg/tls/_9i3uIVDQ3pDRswpm9...

mswphd··on NSA tries to weaken mlkem standardisation?
That was articulated this morning explicitly on the TLS WG, you can see here

https://mailarchive.ietf.org/arch/msg/tls/_9i3uIVDQ3pDRswpm9...

In general most cryptographers don't do hardware. Most cryptographers would do something more conservative. I personally think what chrome is doing with the XWING combiner is fine/sensible.

I do NOT think that stirring up so much trouble over pure ML-KEM is fine/sensible. Especially since it comes after nearly a decade of trying to disrupt the post-quantum transition by DJB (his behavior around the NIST PQC competition). It has made me view him as a bad actor in this space, which is a shame given his previous positive contributions to the field.

RE downgrade attacks: you're right. For some prior downgrade attacks (TLS 1.2), see e.g. LogJam

https://weakdh.org/imperfect-forward-secrecy-ccs15.pdf

My (admittedly hazy) memory of the attack was that they were able to take a client + server who both support "export grade" crypto (say 512-bit finite field DH), then

1. force them to choose this (over cipher suites they may prefer more), then

2. solve the resulting instance before the connection times out, and then

3. use this to rewrite the transcript history to be consistent with one of the sides only supporting 512-bit DH.

This required both sides to support the 512-bit DH though, as well as having the ability to break it on the order of minutes. There is no public estimate that breaking ML-KEM is remotely that small. There are some public repositories of attack records on LWE, e.g.

https://www.latticechallenge.org/lwe_challenge/challenge.php

As you can see, the records are < dimension 100 (though that isn't the only relevant parameter). There might be some records elsewhere that push this mildly higher, but my understsanding is the record attack is

1. definitely << 200, and

2. attacks against ML-KEM have exponential time complexity, so scaling to ~500 would require quadratically more time. This is a huge difference in cryptography, e.g. the difference between a completely broken scheme (say complexity ~2^50-2^60) and AES (~2^120).

mswphd··on NSA tries to weaken mlkem standardisation?
quantum algorithm would make pure ML-KEM bad to support for the NSA. If the NSA has a quantum computer, they would want to delay proliferation of post-quantum schemes as long as possible, so they could get as much milage out of it as possible before people switch over.

Ironically, this (delaying PQC rollout/standardization) is arguably what DJB has been doing the ~decade, and what his current post is doing.

mswphd··on NSA tries to weaken mlkem standardisation?
this RFC is marked "recommended to implement = N". It is not suggesting everyone should use pure ML-KEM. It is suggesting it should be an option, if hybrid encryption is not suitable for certain usecases. Think hardware, where hybrid encryption would require devoting chip area to both SHA2 and SHA3 for no real benefit.
mswphd··on NSA tries to weaken mlkem standardisation?
this is literally what happened with previous NSA meddling though? Both DUAL_EC_DRBG and DES were done "officially" by the NSA.

Additionally, the main authors behind ML-KEM are all european. The design of ML-KEM is "very boring", in the sense that it's essentially the scheme that most (lattice) cryptographers would have suggested. There were 2 other NIST PQC schemes that went very far (New Hope and Saber) that were essentially the same scheme (there were minor technical differences, but it's really not that big).

mswphd··on NSA tries to weaken mlkem standardisation?
the NSA has a history of weakening cryptography in a very specific way, known as "NOBUS"

https://en.wikipedia.org/wiki/NOBUS

DES key-size weakening is consistent with NOBUS (given the computational dominance of the US at the time). DUAL_EC_DRBG is consistent with NOBUS. DES S-box strengthening (vs linear/differential cryptanalysis, I forget which) is also consistent with NOBUS.

There have been *no* proposed mechanism that would allow NSA to have a NOBUS-style attack against ML-KEM.

Separately, this RFC (pure ML-KEM) is marked "recommended to implement = N". It is highly likely all browsers etc will use hybrids. In certain areas (say hardware) it is not free to use a hybrid. You all of a sudden need both a SHA2 and SHA3 implementation, for example. Some organizations that view the threat of quantum computers as more credible may also not want to drag around the ECC component (which is known to be broken, once a CRQC appears. Google and the US government have publicly stated concerns this may occur within the next ~5 years after recent QC breakthroughs).

mswphd··on NSA tries to weaken mlkem standardisation?
this is not an accurate picture of what is happening. Hybrid KEMs are already widely supported within the IETF, and are supported in an RFC with "recommended to implement = yes".

This is about a separate RFC with "recommended to implement = no".

If the IETF was trying to have these positions swapped, it would be consistent with DJBs post. It is not though. His post does not seem to be grounded in reality.

mswphd··on NSA tries to weaken mlkem standardisation?
DJB has for years claimed anyone who disagrees with him is affiliated with the NSA. See for example this post as part of the NIST-PQC competition

https://blog.cr.yp.to/20220805-nsa.html

> Some people seem to be unable to rationally consider the possibility that NSA is sabotaging post-quantum cryptography. I've heard people saying, for example, that submissions to the NIST Post-Quantum Cryptography Standardization Project (NISTPQC) were publicly designed and evaluated by top experts, and that NSA can't have bribed the submission teams. > > Let's look at the facts.

Note that the authors of ML-KEM are overwhelming European.

mswphd··on NSA tries to weaken mlkem standardisation?
The IETF has published the russian TLS 1.2 standard (RFC 9189). This includes Kuznyechik, which is has a certain design choice consistent with it being backdoored.

https://en.wikipedia.org/wiki/Kuznyechik#Cryptanalysis

(the work by Perrin that is mentioned is what I'm referring to).

The (pure) mlkem standard is also marked "recommended to implement = No". people are interested in implementing it. The IETF can't change that. They can try to ensure such implementations are interoperable though.

mswphd··on Kimi K2.7 Code is generally available in GitHub Copilot
dense models are (more) compute heavy, so are generally worse to run on mac. mac tends to be better for (larger) MoE models.

27B dense can fit on a consumer graphics card. Even without getting into various "intrusive" ways to shrink the size of a model (e.g. REAP), something like a NVFP4 quant of Qwen3.6 27b

https://huggingface.co/nvidia/Qwen3.6-27B-NVFP4

should fit within ~22GB of VRAM. So easily on a 5090. It would also fit on a 3090/4090, but iirc they don't have NVFP4 natively, so you would want a different quant for them.

you can see /r/LocalLLama for some discussions. See this (random) post about Qwen3.6-27B on a 3090 at ~100 tok/s

https://www.reddit.com/r/LocalLLaMA/comments/1ujo46r/qwen_36...

Note that it is possible you could still do this stuff with a mac, as there are ways of hooking up a eGPU to macs and using it for inference. My understanding is they're all fairly hacky though, so it would likely be preferrable to just get a 3090 (or a non-nvidia option, e.g. an AMD r9700 pro has ~32GB of VRAM for much cheaper than a 5090.

https://www.reddit.com/r/LocalLLaMA/comments/1u50hnm/qwen_27...

that seems considerably slower though (~30 tok/s). I don't know if that's an outlier/misconfigured setup or what. In general there will be much better resources for local setups using 3090s, as they're quite popular. Note that 3090s (but not 4090s nor 5090s) have NVLink, so you can network the cards fairly effectively. For this reason 2x 3090 setups are fairly popular as well. I've heard that club 3090 makes that relatively straightforward

https://github.com/noonghunna/club-3090

but don't have experience myself.

mswphd··on Qwen 3.6 27B is the sweet spot for local development
CPU moe offloading. see e.g.

https://www.reddit.com/r/LocalLLaMA/comments/1t9eo83/running...

mswphd··on Scars mark Britain's economy 10 years after Brexit vote
I've generally heard it as manufacturing woes due to competition with China. in particular germany used to sell a significant number of cars to china, and now is being outcompeted (both in china and many other locations) by chinese cards. plausibly true in other manufacturing areas, I don't know.
mswphd··on French physicist and media star loses doctorate after plagiarism investigation
that's broadly true, but there are some areas of CS that are at least as close (say at a minimum PL theory). it's also less math heavy than e.g. complexity theory (though that's admittedly smaller). It can also be less math-heavy than learning theory. This all depends on the type of cryptography as well, especially since it can depend on the region (american cryptography is more theoretical than european cryptography, for example).
mswphd··on US holds off blacklisting DeepSeek, more than 100 firms deemed security risks
I'm confused. China has been in a fairly bad recession the last ~2 years (their housing bubble popping). Why are we assuming that recessions can only happen in the US?

I'm also confused how China managed to convince so many US VC's to spend an insane amount on a technology with "no moat". China exporting cheap AI hurts American hyperscalars. But it doesn't induce the behavior in American hyperscalars that causes them to be vulnerable to cheap AI. It seems kind of patronizing to point the finger at China, rather than acknowledge the American (potential) misallocation of resources.

mswphd··on US holds off blacklisting DeepSeek, more than 100 firms deemed security risks
this is not an accurate picture of Chinese industrial policy. In fact, you could argue they have the opposite problem. Their industrial policy encourages too many companies to enter a space, where the resulting competition kills off profit margins for whichever companies end up surviving until the end. This is exactly what we end up seeing with extremely cheap Chinese goods.

If china anointed one company per sector, they would have no reason to be so cost competitive globally. There would be no structural cause for Chinese products to outcompete the rest of the world. You can see some of this in the US, where these kinds of anointed companies exist (say e.g. Boeing/other defense contractors, at least post the 90's). They are (famously) not particularly cost competitive. This is also exactly what you'd expect economically.

mswphd··on US holds off blacklisting DeepSeek, more than 100 firms deemed security risks
this is a justification for why one frontier lab would have extremely high spend rates. There is >1 frontier lab though.

More explicitly: if the Chinese can get near-leading performance models at a fraction of the cost by stealing from Anthropic, why doesn't OpenAI? Lord knows they could use the extra cash.

mswphd··on US holds off blacklisting DeepSeek, more than 100 firms deemed security risks
As an explicit example, major revenue streams that Tesla (used to) take advantage of are

1. the EV tax credit, and

2. carbon credits

so the richest man in the world/the US had significant tailwinds for a central business venture of his via either directly taking money from the government, or taking money from other companies due to the government requiring they give him money.

mswphd··on French physicist and media star loses doctorate after plagiarism investigation
CS can (but not frequently) have the revolutionary result you mention as well. A candidate Fully Homomorphic Encryption scheme was first detailed in Craig Gentry's thesis, for example. That being said, this is much less common than a

1. literal stapler thesis, or

2. cleaned up version of a stapler thesis (e.g. rewrite of several previous publications to give broader context etc)

mswphd··on How memory safety CVEs differ between Rust and C/C++
interesting links

> Others think someone from the Rust (programming language, not video game) development community was responsible due to how critical René has been of that project, but *those claims are entirely unsubstantiated*

huh

> The guy that tried to SWAT me was extremely enthused about Rust: never shut up about it.

hm. the guy was also ostensibly a male. should we ban all men from HN? maybe they should be fired and shunned and cast out of society.

mswphd··on Anthropic apologizes for invisible Claude Fable guardrails
This kind of reasoning leads you to reasoning that if he was an ineffective fraudster, it would be less moral, as he would have bought less mosquito nets. So it’s not only moral to do fraud, but you most extremely competently do fraud.

I think this being a reasonable utilitarian point to make is not a point in utilitarianism’s favor.

mswphd··on How Terry Tao became an evangelist for AI in math
the way to interpret the gigantic lean proof is not by inlining each lemma, looking at all the lines, and thinking "yeah that's a lot". That's also not the way to read a paper.

Instead, you proceed in layers of abstraction. For example

1. the main claim may rest on some set of sub-claims, as well as some local (to teh main claim) work to "patch things together"

2. each of those sub-claims themselves may require other sub-claims + local work, etc

These can be collected into a dependency graph. In lean, this is often called a "blueprint". Here is the blueprint for the formalization of the Polynomial Frieman-Rusza conjecture (now a theorem, by Gowers, Green, Manners, and Tao).

https://teorth.github.io/pfr/blueprint/

This layer of abstractions is (roughly) equivalent a different way to format mathematics. You could remove the Lean component (let alone any AI), and create such a dependency graph for a paper. I would argue this is a clearer way to format mathematics (again, ignoring both the formal verification applications of it, as well as AI).

Any mathematics paper intrinsically has a graph such as this underlying it, and tries to make the various linkages in the graph clear via prose. Prose is only so powerful a way to organize things. I'm sure you're familiar with the way early mathematicians would describe various formula (e.g. the quadratic formula) via prose. It is very hard to understand.

Separately from this dependency-graph perspective, you can do things like

1. add formal verification. Now, each component in the dependency graph is verifiable with high confidence (though harder to write and read). This has some benefits and downsides. Harder to write and read is bad. Being able to have high confidence in the veracity of the result is *very* good. It allows larger collaborations in mathematics. Previously, a large collaboration would require all mathematicians to trust eachother to a large extent. This is (practically) difficult.

2. when each component can now be verified to high accuracy, you can now throw AI at it. I won't extoll the virtue of this. There are parts of it that seem interesting, but many "AI for Math" things currently are stil producing unformalized papers (in prose).

Maybe the main thing I'd say is that this type of "graph structure, with each component trusted" is already implicitly what mathematicians do. You write papers that cite other papers etc. Except now, instead of needing to look for status signals to trust papers (or invest personal effort), you can look for another (honestly fairer) signal to trust papers. So there's a sense in which formalization allows for the democratization of mathematics. I do think there's something beautiful about that.

mswphd··on Anthropic apologizes for invisible Claude Fable guardrails
The first half of your answer presupposes some platonic utilitarian calculus that, if it were applied correctly, would yield moral outcomes. This is very hard to believe. If I look at notable/well-known examples of EA-affiliated people, it is hard to skip by members such as SBF. Did he correctly apply the utilitarian calculus?

It is relatively easy to take the proceeds of a massive fraud, buy a relatively small (as a percentage of the fraud) $ amount of mosquito nets, and save more lives than the lives impacted by your massive theft. Is this a correct application of the utilitarian calculus? What sort of data would we need a priori to do this calculation "correctly"? Do you think he had a careful estimate of the suicide rate of victims of ponzi schemes before perpetuating the fraud, or would any suicide rate have made the decision net [pun intended] moral, as any such victim of fraud would lead to >> 1 net purchased (so you would almost always net save lives).

The above is of course snarky. It is also a best-effort way of analyzing a notable utilitarian's actions. I do not think it would be difficult at all to use this type of argument to argue that SBF's actions net raised utility in the world. If only we all would become fraudsters, then we could truly live in Omelas --- a notable utilitarian paradise.

mswphd··on Apple Core AI Framework
there's pros and cons to it for them. Clearly, they get good branding (at least in enthusiast circles). Perhaps more important is they get community work on optimization. There have been significant performance uplifts on the Qwen3.6 models from the open-source community since they were launched (at a minimum, multi-token prediction is now working with them. It is almost a 2x token generation speedup)

https://www.reddit.com/r/LocalLLM/comments/1ti9w4o/qwen3635b...

mswphd··on Let's Encrypt bans certificate usage in any US sanctioned territory [pdf]
love thought-terminating cliches. really helps keep from actually thinking ever.
mswphd··on An introduction to functional analysis for science and engineering
both no in principle, and when you're used to reading LaTeX, word is ugly. It's a milder form of how if these notes were handwritten it wouldn't matter, but it would also be less appealing than them being typeset well.
mswphd··on Apple Core AI Framework
Yes and no.

Qwen 3.5 was released 3/2/2026. It includes models up to a 397B-A17B model

https://huggingface.co/collections/Qwen/qwen35

A day afterwards, a high-up technical leader working on Qwen was let go

https://techcrunch.com/2026/03/03/alibabas-qwen-tech-lead-st...

The more recent Qwen 3.6 was released on 4/16

https://huggingface.co/collections/Qwen/qwen36

This does not include any particularly large models. But the models it contains (Qwen3.6 27B and Qwen3.6 35B-A3B) are the local models people have been very excited about lately. So they didn't release any larger models, and the models people praise so much are from this most recent release.

← PreviousPage 4 of 8Next →