Good point. Note however that PIR is a rather restricted form of search (e.g., with no privacy for the server), but even so, DEPIR has polylog(n) queries (not log n), and requires superlinear preprocessing and a polynomial blowup in the size of the database. I think recent concrete estimates are around a petabyte of storage for a database of 2^20 words. So as you say, pretty impractical.
There is an even more fundamental reason why FHE cannot realistically be used for arbitrary computation: it is that some computations have much larger asymptomatic complexity on encrypted data compared to plaintext.
A critical example is database search: searching through a database on n elements is normally done in O(log n), but it becomes O(n) when the search key is encrypted. This means that fully homomorphic Google search is fundamentally impractical, although the same cannot be said of fully homomorphic DNN inference.
While not mentioned by the author, there is an alternate reason why finite field DH can be seen as a special case of ECDH, kind of: namely, there exists special elliptic curves (actual, smooth projective curves) that do have an efficiently computable endomorphism to a suitable form of the multiplicative group, via pairings. This is in essence the MOV attack against the XTR cryptosystem. That doesn't fit neatly in OP's framework, though, because the map isn't a morphism of algebraic groups (it is efficient for other reasons), and it is cheating a little bit, because the inverse map isn't efficiently computable.
Another point that the author glosses over a bit is that higher dimensional abelian varieties offer other instances of DH that are genuinely different from ECDH, and that are occasionally useful (mostly the case of Jacobians of hyperelliptic curves of genus 2). There isn't really a trick to make an arbitrary hyperelliptic curve DH/abelian variety DH instance a special case of ECDH: if anything, the relationship would be in the reverse direction.
Elligator is only tangentially relevant to the hashing problem. If "doesn't have a problematic structure" is understood in a weak sense, then this was already solved by Shallue and van de Woestijne almost a decade prior to the Elligator paper. And if it is understood in the stronger sense of indifferentiability, then Elligator by itself doesn't actually fit the bill, and you need something like the Brier et al. approach or SwiftEC.
The steganography stuff is the only actually novel contribution of the Elligator paper.
In that spirit, my pet "a monad is a monoid in the category of endofunctors, duh"-style one-line explanation of the Fourier transform is that it's just the decomposition in the common (Hilbert) eigenbasis for all translation operators. It makes it surprisingly clear (to some) why it is a both natural and important construction.
A map of algebraic curves is not a special case of a map between two sets. There aren't really source and destination sets to speak of. The fact that it is given by polynomials really is a definition.
The moral "justification" of the definition is something like "algebraic geometry is precisely the study of such objects" or "we want definitions that are stable under ring base change, and this implies polynomials", etc., but we don't formally need to justify definitions.
[One could take a different route to defining those things, in which this becomes a theorem instead of a definition. For example one can define algebraic curves over a field k as contravariant functors from k-algebras to sets satisfying certain additional properties, and then maps of algebraic curves are natural transformations between those functors. The fact that they are given by polynomial equations is then a theorem. Just stating the "additional properties" for a curve is a rather daunting task, though, unfortunately.]
The hardness of discrete logs over fields doesn't have much to do with the hardness of elliptic curve discrete logs. At this stage, I don't think we have any evidence that curves over binary fields are less secure than over prime fields, especially for cryptographically relevant curve sizes.
(The situation is different for pairing-friendly elliptic curves, of course, but that's a different kettle of fish).
I'm not sure what specific scheme you have in mind, but while FHE for Turing machines does exist, it is really, really hard to instantiate. A construction with some restrictions and requiring a massive amount of preprocessing is given in Goldwasser et al.'s famous paper on reusable garbled circuits, and it already uses succinct functional encryption as a building block; and for the stronger notion of FHE for TM you basically need obfuscation. So thinking about implementing any of this seems somewhat premature to me.
I don't think most of the issues with freedom of speech in France would be of much concern to a putative startup founder, but they are real.
For example, "expressing support for acts of terror" is an imprisonable offense, and it has been interpreted incredibly broadly by the courts, to the point that drunk people have been sent to prison for years over tasteless jokes. Similarly, simply browsing websites that are deemed in support of terrorism: a man from Chartres recently received a two-year sentence for the latter.
It's fair to say that the current climate is pretty Orwellian. But if you're not a brown person or a Muslim, you're not what prosecutors are after.
> I'm of the opinion that worked examples are often worse than no documentation.
That's completely baffling to me so I'd be really curious to hear your reasons (or those of someone who shares that opinion, as there are others in the thread apparently).
When learning about an abstract notion, it has been my experience that having good examples in mind (in the sense that they are not too complex, but non-trivial enough to illustrate the relevant aspect of the notion at hand) is very helpful, if not essential, for comprehension. All the more so for very abstract subjects (e.g. back in grad school I was studying algebraic geometry, and you can't go very far in that subject trying to prove things about functors on the category of rings without examples in mind that connect the abstract nonsense to some actual geometric meaning).
Speaking of abstract nonsense, by the way, under the Curry-Howard isomorphism, publishing a library with type signatures but no worked out example is equivalent to publishing a mathematical paper consisting entirely of lemmas with no example of how to combine them to prove something interesting (in fact, it's worse, because the expressiveness of the Haskell type system obviously pales in comparison to the language of mathematical papers). I would almost certainly reject a paper like that if I received one for review, and I expect most referees would too.
The claim was that they are independent, in the sense that they do not depend on monied interests for their financial survival, and have a real commitment to investigative journalism. I think even their opponents will acknowledge that they won't shy away from running a damaging story on anyone regardless of which "team" they belong to. (Disclaimer: also a subscriber here).
On the other hand, what they are not is "unbiased" or "neutral". They are quite vocal about their political views. On most issues their stance is usually around the leftmost end of the French MSM Overton window, if that means anything. I happen to disagree with quite a few of these views, but I have a lot of respect both for their journalistic integrity and for the role they play within the French media.
Regular humans have, for over half a century, possessed the ability to annihilate the entirety of civilization by basically pushing a button. So it always amazes me when people feel the need to make science fictional assumptions like AGI in their doomsday scenarios.
> Elsevier's role isn't finding collaborators - it's finding reviewers
This is also not true. It's usually journal editors who find reviewers. This is mostly unpaid work as well (publishers tend to chip in a bit for editorial board meetings, but that's about it).
Scientific publishers provide very, very little value to the scientific community. The reason why researchers want to publish in Journal X is that it has a good reputation, which is mostly a function of the editorial board's quality standards, and even more so, of Journal X's past publications (often dating back to way before Elsevier or whoever else actually acquired it).
On a more serious note, it's interesting to reread his poem _America_, which was certainly written more as an aspiration than a description at the time. However, this election makes you wonder whether the aspiration is even there anymore (from either side, if we're being honest).
| Centre of equal daughters, equal sons,
| All, all alike endear’d, grown, ungrown, young or old,
| Strong, ample, fair, enduring, capable, rich,
| Perennial with the Earth, with Freedom, Law and Love,
| A grand, sane, towering, seated Mother,
| Chair’d in the adamant of Time.
Here in Japan, the NURO Hikari service of Sony Network Communications offers FTTH with 10 Gbps downlink and 2.5 Gbps uplink speeds for around ¥6500 (~65 USD) per month. It's only available in the central wards of Tokyo and a part of Kanagawa prefecture, but you can get it right now.
Obfuscation is different from homomorphic encryption, and in some sense much more powerful.
With homomorphic encryption, Alice can send some secret data to Bob in encrypted form, and let Bob carry out computation on that encrypted data. However, the result of the computation remains encrypted, and only Alice's private key can decrypt the result.
By contrast, obfuscation allows Alice to give Bob a program that contains some secret information (such as cryptographic keys) in such a way that Bob can run it (without any further interaction with Alice) on any inputs of his choice, and get the result in the clear. However, he cannot learn anything about the hidden secret information other than what is revealed by the input-output pairs he has obtained.
It's not hard to see that obfuscation gives you homomorphic encryption for free (you can probably get a rough idea of how to do it based on the somewhat imprecise descriptions above), but we don't know how to go in the other direction. (Current obfuscation candidates do use fully homomorphic encryption under the hood, but they need to rely on much more than that).
Not completely clear to me what you mean by "calculated to be true", but you may want to look at the difference between computational and statistical zero knowledge. A computational ZK proof hides the witness from computationally bounded (i.e. probabilistic polynomial time) adversaries. Statistical ZK, on the other hand, hides the witness from any adversary, even if they can carry out an unbounded amount of computations (there are slight subtleties there depending on the precise security model but that's the basic idea).