Quasipolynomial Cryptanalysis of the McEliece Cryptosystem [pdf](eprint.iacr.org) |
Quasipolynomial Cryptanalysis of the McEliece Cryptosystem [pdf](eprint.iacr.org) |
Classic McEliece was explicitly designed not to rely on distinguishing resistance for security. See this rebuttal of an earlier distinguishing attack: https://classic.mceliece.org/mceliece-610-20260623.pdf
See also https://postquantum.com/security-pqc/mceliece-quasipolynomia... ("Public-key pseudorandomness is a property other people assumed, not one Classic McEliece promised. A distinguisher running in 2114 operations violates no claim the team has ever made, and anyone reporting this as a break should say which claim they think fell.")