That’s good, but I think we can agree that if the application developers can work around the holes left by the protocol developers, that’s a form of future-proofing. Which is probably not a bad thing either way.
1 Like
In regards to this, I’d actually like to say that lattice schemes could potentially be reliable as well. For instance, the NTRU patent was filed in 1997 whereas the Curve25519 paper was published in 2005.
I’d argue that while SPHINCS+ is likely the most reliable scheme available, lattices are also reliable. Namely, I’d argue for the following lattice schemes:
ML-DSA/Dilithium (still incredibly arguable)
Falcon
Possibly Raccoon
Additionally, I’d like to take a look at FAEST slightly more, as it’s also conservative without the signatures being as large.
All of these schemes (excluding Raccoon) are helpfully arranged here at the signature zoo.
1 Like