From discrete-log to lattices: maybe the real lessons were our broken schemes along the way?

Published in CFAIL 2020, 2020