KF attacks NTRU-1-tinyfg. SS proves NTRU-1-hugefg is as strong as RLWE-1. NTRU-1-normalfg _may be_ weaker, just like RLWE-2 _may be_ weaker.

New Hope, Kyber, etc. could be above NTRU in strength, or equal, OR BELOW. You keep falsely claiming that the last possibility can't exist.


Ring-LWE is defined to allow any number of samples, and yet typical "Ring-LWE-based" cryptosystems ignore this fact in choosing parameters.

Ring-LWE has been parameterized by number of samples since its inception, and concrete proposals absolutely do pay attention to this.

You ignore RLWE-2 (2 samples) being maybe weaker than RLWE-1, while you complain about NTRU-1 being maybe weaker than RLWE-1. Incoherent.

RLWE-2 could be easier than 1, though we have no evidence of this. We *do* have evidence that NTRU-1 is easier than both: the KF attack.