Live data from Hacker News

Cryptographic vulnerabilities in IOTA

medium.com

21–30 of 73 posts

Re: Cryptographic vulnerabilities in IOTA

#21
post #20
post #14

The thing that I think should really worry you is that the reaction among the professional cryptographers to this (or at least the dozens I talk to on Slack and Twitter) is "well, that's cryptocurrency for you". If you have the impression that serious cryptographers are knee deep in the problem space of trying to make sure cryptocurrencies are actually secure, revise your expectations.

This curl function actually came up in conversation with someone about a month ago. We figured that there was no way the core transformation was secure, and that was about the extent of our interest in it.

Right! I think people have a misapprehension that working cryptographers feel a kind of moral urgency to ensure that popular software is cryptographically sound. When confronted with insane stuff like IOTA, most cryptographers just drink.

Re: Cryptographic vulnerabilities in IOTA

#23
IOTA is trash for this and other reasons. You should short it. Issues:

1. Double spends are devastating and easy, since they permanently split the tangle.

2. With no transaction limit, syncing from the beginning of time will take forever.

3. With no transaction limit, keeping up with network traffic will be impossible. (Especially on IoT devices.

4a. Nobody is going to use power and die space on IoT devices for the PoW chip.

4b. Or, alternately, if, as they claim, the PoW chip will take very little die space and very little power, the network will be destroyed outright by non-IoT PoW chips spamming the network.

5. There is currently a coordinator which confirms transactions. It is not P2P. If they remove the coordinator, I could write code that destroys the network by issuing TiB of transactions per day, making it impossible to sync/keep up.

6. Mesh networks of the type that they envisage deploying IOTA on are not widely deployed, and it's not clear that they will ever be widely deployed.

7. Tip selection does not converge.

Re: Cryptographic vulnerabilities in IOTA

#24

Does anyone know if the IOTA devs ever wrote down a justification for using a hand-rolled hash instead of, like, SHA-256? If so, can you link it in a comment? EDIT: I feel compelled to explicitly say that this was a mind-bogglingly stupid thing to do, and there is almost no way to justify it. I'm just curious what they thought they were accomplishing.

The IOTA devs are deluded. Here's there justification:

"Creating a new cryptographic hash function is no trivial undertaking, even when it is being built on preexisting world class standards. “Don’t roll your own crypto” is a compulsory uttered mantra that serves as a good guiding principle for 99.9% of projects, but there are exceptions to the rule. When spearheading technology for a new paradigm this statement is no longer axiomatic. Progress must march on."

Re: Cryptographic vulnerabilities in IOTA

#25
Sigh.

Exhibit A: Don't roll your own crypto...we don't just say it because it's fun.

Kudos to the authors for not weaponizing the vulnerability for profit. There was no sound basis for the developers to design their own hash function, and it was a collosal mistake. It's not as if any of the other hash functions were inadequate for their security or performance needs.

Frankly, I don't know if I should blame ignorance or hubris in this situation.

Re: Cryptographic vulnerabilities in IOTA

#27

IOTA is trash for this and other reasons. You should short it. Issues: 1. Double spends are devastating and easy, since they permanently split the tangle. 2. With no transaction limit, syncing from the beginning of time will take forever. 3. With no transaction limit, keeping up with network traffic will be impossible. (Especially on IoT devices. 4a. Nobody is going to use power and die space on IoT devices for the P…

Is there a reliable exchange offering reliable short contracts?

Re: Cryptographic vulnerabilities in IOTA

#28
post #14

The thing that I think should really worry you is that the reaction among the professional cryptographers to this (or at least the dozens I talk to on Slack and Twitter) is "well, that's cryptocurrency for you". If you have the impression that serious cryptographers are knee deep in the problem space of trying to make sure cryptocurrencies are actually secure, revise your expectations.

The ZCash team is pretty serious: https://z.cash/team.html

Re: Cryptographic vulnerabilities in IOTA

#29
post #14

The thing that I think should really worry you is that the reaction among the professional cryptographers to this (or at least the dozens I talk to on Slack and Twitter) is "well, that's cryptocurrency for you". If you have the impression that serious cryptographers are knee deep in the problem space of trying to make sure cryptocurrencies are actually secure, revise your expectations.

> If you have the impression that serious cryptographers are knee deep in the problem space of trying to make sure cryptocurrencies are actually secure, revise your expectations.

Confidence in cryptocurrencies come from their ability to be patched.

Every death knell observation merely makes them stronger. People understood that in 2011 and acquired cryptocurrency, they understand that in 2017 and acquire cryptocurrency, they would prefer widespread self perpetuating ignorance continues while they acquire cryptocurrency.

Re: Cryptographic vulnerabilities in IOTA

#30
post #4

I even think that the issues with new cryptocurrencies is underestimated in the article. The problem goes beyond the cryptographic aspect to game theoretical challenges: the cryptographic protocols could be perfect and yet the cryptocurrency be insecure or offer a low security threshold. For example, Bitcoin is perfect from the cryptographic perspective but its security threshold is around 33% [1]. Last year we also…

It's not really a vulnerability. Miners don't have an incentive to destroy the currency with a >50% attack, they are heavily invested in it.

If the thing protecting the network is the self interest and good behavior of the miners then people should stop saying that the thing protecting the network is the awesome mining power of the network.
Post reply on HN