Quasipolynomially breaks the key distribution of Classic McEliece, then tightens concrete attack costs and a heuristic decrypt attack.
1 comment
If the attack is on Classic McEliece's key distribution, does that mean the underlying code stays hard and only the way keys are generated or sampled becomes the weak point?