Green: schemes at 128-bit security may really offer only 96-108 bits
matthew_d_green · x · 2026-10-09
In a follow-up on what "losing public-key encryption" means, Matthew Green notes the more modest effect: several schemes previously agreed to be "good enough" at the 128-bit security level may no longer be, perhaps offering only 96- or 108-bit security. A warning for re-evaluating standardized cryptographic schemes.
More from Research
- Ex-self-driving ML engineer writes long-form on the practice of semi-supervision — Visual_Ability · 2026-10-09
- RLVR misses 'all minimal correct answers' problems; new credit assignment doubles finds — thoma_gu · 2026-10-09
- Debunked: AI did not solve the Millennium Prize Navier-Stokes problem — gerardsans · 2026-10-09
- New open-source 3JSBench evaluates LLMs on generating coherent Three.js 3D assets — ycombinator · 2026-10-09
- Moonworks' Lunara: Sub-10B Diffusion Mixture Transformer Tops Aesthetic and Human Blind Evaluations — paper-crow · 2026-10-09
- Study: Local domains take 41.4% of AI citations in Brazil, 38.3% in UK across ChatGPT and Gemini — gaganghotra_ · 2026-10-09