Does anyone know if the IOTA devs ever wrote down a justification for using a hand-rolled hash instead of, like, SHA-256? If so, can you link it in a comment? EDIT: I feel compelled to explicitly say that this was a mind-bogglingly stupid thing to do, and there is almost no way to justify it. I'm just curious what they thought they were accomplishing.
The justification can be found on the Reddit: "Because we needed an efficient hash function for IoT and the future of ternary computing (memristors, spintronics, optical computing and the trend in Artificial Neural Networks) This has been known since before we even began the project. I spoke with the Keccak team about this all the way back in early 2015 before a code of IOTA was written" Source: https://gyazo.com/03c…
Cryptographic vulnerabilities in IOTA
41–50 of 73 posts
Re: Cryptographic vulnerabilities in IOTA
#42Earlier quoted context omitted.
Is there a reliable exchange offering reliable short contracts?
IOTA is traded on Bitfinex, which I think allows shorting, although I've never done it. One thing to keep in mind though is that the market is not particularly rational, so even though I think IOTA is doomed in the long term, in the short term it could go up, because markets. So if you do decide to short, make sure to figure out what degree of leverage is important, and what your appetite for risk is.
Re: Cryptographic vulnerabilities in IOTA
#43The thing that I think should really worry you is that the reaction among the professional cryptographers to this (or at least the dozens I talk to on Slack and Twitter) is "well, that's cryptocurrency for you". If you have the impression that serious cryptographers are knee deep in the problem space of trying to make sure cryptocurrencies are actually secure, revise your expectations.
The ZCash team is pretty serious: https://z.cash/team.html
Re: Cryptographic vulnerabilities in IOTA
#44Earlier quoted context omitted.
Moreover, rolling their own hash function (which is what they did) is a rookie mistake.
Note that IOTA is a system based on ternary rather than binary, which itself is a WTF. Then on top of that, the hash function they replaced the broken one with is a wrapping of SHA3 (Keccak) with ternary. So again, they rolled their own crypto, although in a (hopefully!) more minor way. Unfortunately, doing review is a lot of hard work - I know the people involved and they had to waste time and money talking to lawye…
Re: Cryptographic vulnerabilities in IOTA
#45Earlier quoted context omitted.
Is there a reliable exchange offering reliable short contracts?
IOTA is traded on Bitfinex, which I think allows shorting, although I've never done it. One thing to keep in mind though is that the market is not particularly rational, so even though I think IOTA is doomed in the long term, in the short term it could go up, because markets. So if you do decide to short, make sure to figure out what degree of leverage is important, and what your appetite for risk is.
Re: Cryptographic vulnerabilities in IOTA
#46IOTA is trash for this and other reasons. You should short it. Issues: 1. Double spends are devastating and easy, since they permanently split the tangle. 2. With no transaction limit, syncing from the beginning of time will take forever. 3. With no transaction limit, keeping up with network traffic will be impossible. (Especially on IoT devices. 4a. Nobody is going to use power and die space on IoT devices for the P…
1: Flat out lie, this has never happened. Prove it otherwise.
2: IOTA uses snapshotting, you don't need to sync from the "beginning"
3: Untrue
4: Untrue
5: The only thing so far you've said that's true
6: Untrue
Re: Cryptographic vulnerabilities in IOTA
#47Re: Cryptographic vulnerabilities in IOTA
#48IOTA is trash for this and other reasons. You should short it. Issues: 1. Double spends are devastating and easy, since they permanently split the tangle. 2. With no transaction limit, syncing from the beginning of time will take forever. 3. With no transaction limit, keeping up with network traffic will be impossible. (Especially on IoT devices. 4a. Nobody is going to use power and die space on IoT devices for the P…
This guy is spreading lies. 1: Flat out lie, this has never happened. Prove it otherwise. 2: IOTA uses snapshotting, you don't need to sync from the "beginning" 3: Untrue 4: Untrue 5: The only thing so far you've said that's true 6: Untrue
Re: Cryptographic vulnerabilities in IOTA
#49This includes the subtle features and policies relating to control of the money (coin) supply, growth and hence inflation.
Messing with a time proven recipe is going to result in more and more of these revelations.
Re: Cryptographic vulnerabilities in IOTA
#50Does anyone know if the IOTA devs ever wrote down a justification for using a hand-rolled hash instead of, like, SHA-256? If so, can you link it in a comment? EDIT: I feel compelled to explicitly say that this was a mind-bogglingly stupid thing to do, and there is almost no way to justify it. I'm just curious what they thought they were accomplishing.
Their motivation is really being able to claim an "improved" and "different" cryptocurrency to an audience of promoters, investors and speculators.