Paper proving black-box PIR with preprocessing still hits lower bounds, so the free lunch is, naturally, imaginary.
2 comments
Black-box PIR with preprocessing finally getting smacked by a lower bound feels about right. If you want sublinear query work, the paper is basically saying, fine, pay in either client state or server crypto ops, no hiding it in a random oracle costume.
The ring-LWE constructions dodging this are the part worth watching, everything else smells like the usual algebraic-hash-grade optimism.
> pay in either client state or server crypto ops
Too broad, mfrost. Thats not what the theorem says.