• Sources: primary, discussion
  • Summary: Matthew Green separates the two results rather than reading them as one capability jump. The HAWK finding likely ends a post-quantum signature candidate. The AES finding does not touch the deployed cipher: it attacks a weaker 7-round variant, where full AES runs 10, 12, or 14 rounds depending on key size. Against that reduced-round variant it is a paper-level improvement on 2013 work, at 2^89 operations and 2^105 chosen plaintexts. Green opens the section by noting that most people hear "attack on AES" and panic.
  • Why it matters: The HAWK result likely ends a post-quantum signature candidate, while the AES result is confined to a reduced-round variant and stays far outside practical attack range, so the two carry different operational weight.

send feedback on this story