Dear directors of the IACR,
I turn to you again with the topic of incorrect review procedures for
IACR sponsored conferences. I find it completely unacceptable that I
did not get any response from your part when I sent you two complaints
about the incorrect review procedures for CHES 2006. As I suspect that
you will again not bother to respond, I make this letter public.
I want to point out that two of the papers whose rejection I had
complained about last year have been accepted for IACR sponsored
conferences this year, so evidently the papers were not completely off
the mark.
This year I had submitted to CHES a paper which showed that the
security proof of the paper "A provably secure true random number
generator with built-in tolerance to active attacks" by Sunar, Martin,
and Stinson is invalid and that the practical implementation of the
generator described "FPAG vendor agnostic true random number
generator" by Schellekens, Preneel, and Verbauwhede does also not work
as claimed. The one negative review I got said that my experiments
which showed strong statistical dependencies between ring oscillators
implemented on the same FPGA, were not valid, as I had used ring
oscillators of equal lengths. This is quite an absurd objection, as
both papers use ring oscillators of equal length, just as I did for my
experiments.
I really think that papers should not be rejected for reasons contrary
to the facts, so I sent a letter of complaint to the program chairs.
First, I got no response, but when I complained again, I got a
response from Professor Verbauwhede, that she does not want to
interfere with the review of individual papers. I find this refusal to
take any responsibility inadmissible. As she had coauthored one of the
papers concerned, she knew that ring oscillators of equal lengths were
used, and that the objection by the reviewer was incorrect.
Where is the responsibility for reviews at IACR conferences? The
reviewers write, under the cloak of anonymity, whatever comes to their
mind. The program chairs do not want to take any responsibility. And
the directors of the IACR do not want to take any responsibility
either. So we have a system of three levels of irresponsibility for
IACR conferences.
You should fix this problem!
Yours sincerely
Markus Dichtl


|