Subject: Re: [pqc-forum] ROUND 3 OFFICIAL COMMENT: Classic McEliece From: Ruben Niederhagen Date: Tue, 29 Jun 2021 15:22:02 +0200 To: pqc-forum , pqc-comments@nist.gov Message-ID: User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:78.0) Gecko/20100101 Thunderbird/78.11.0 Statement by the Classic McEliece team: The Classic McEliece submission document states on page 46: "[Bernstein, Lange, and Peters. 2008] reported that its attack uses 2^266.94 bit operations to break the (13,6960,119) parameter set." However, Kirk Fleming brought to our attention that this quoted attack cost is for a similar parameter set with the same length, dimension, and degree - but for adding 121 errors during encryption and not 119 errors as in our case. We correct the corresponding sentence to: "[Bernstein, Lange, and Peters. 2008] reported that its attack uses 2^266.94 bit operations to break a related (13,6960,119) parameter set with 121 errors."