2016.07.26 13:14:40 (757896914612391936) from Daniel J. Bernstein:
Lattice salesmen continue to (1) claim PQ and (2) point to Gentry's STOC 2009 FHE paper, not mentioning the poly-time PQ break of the paper.
2016.07.26 13:20:09 (757898296358731776) from Daniel J. Bernstein:
Lattice salesmen proudly advertise GGH multilinear maps and IO, but then say "Bad systems! No theorems!" when the security claims crumble.
2016.07.26 13:32:10 (757901320158314496) from Daniel J. Bernstein:
Lattice salesmen claim "hardness guarantees" for LWE/Ring-LWE while "forgetting" to emphasize critical limitations, such as HUGE key sizes.
2016.07.26 13:35:00 (757902033051611136) from Daniel J. Bernstein:
When users fall prey to this bait and switch, mixing up practical Ring-LWE with HUGE Ring-LWE, lattice salesmen deny responsibility.
2016.07.26 13:42:45 (757903981456744448) from Daniel J. Bernstein:
Lattice salesmen pretend that attacks are well understood, and respond to research with denial. Why am I reminded of quantum cryptographers?