Live data from Hacker News

Cryptographic vulnerabilities in IOTA

medium.com

41–50 of 73 posts

Re: Cryptographic vulnerabilities in IOTA

#41
post #39

Does anyone know if the IOTA devs ever wrote down a justification for using a hand-rolled hash instead of, like, SHA-256? If so, can you link it in a comment? EDIT: I feel compelled to explicitly say that this was a mind-bogglingly stupid thing to do, and there is almost no way to justify it. I'm just curious what they thought they were accomplishing.

The justification can be found on the Reddit: "Because we needed an efficient hash function for IoT and the future of ternary computing (memristors, spintronics, optical computing and the trend in Artificial Neural Networks) This has been known since before we even began the project. I spoke with the Keccak team about this all the way back in early 2015 before a code of IOTA was written" Source: https://gyazo.com/03c…

Because of fidget spinners and the cloud, got it.

Re: Cryptographic vulnerabilities in IOTA

#42

Earlier quoted context omitted.

Is there a reliable exchange offering reliable short contracts?

IOTA is traded on Bitfinex, which I think allows shorting, although I've never done it. One thing to keep in mind though is that the market is not particularly rational, so even though I think IOTA is doomed in the long term, in the short term it could go up, because markets. So if you do decide to short, make sure to figure out what degree of leverage is important, and what your appetite for risk is.

You can only short on Bitfinex if you are not in the US.

Re: Cryptographic vulnerabilities in IOTA

#43
post #28
post #14

The thing that I think should really worry you is that the reaction among the professional cryptographers to this (or at least the dozens I talk to on Slack and Twitter) is "well, that's cryptocurrency for you". If you have the impression that serious cryptographers are knee deep in the problem space of trying to make sure cryptocurrencies are actually secure, revise your expectations.

The ZCash team is pretty serious: https://z.cash/team.html

[deleted]

Re: Cryptographic vulnerabilities in IOTA

#44
post #3

Earlier quoted context omitted.

Moreover, rolling their own hash function (which is what they did) is a rookie mistake.

Note that IOTA is a system based on ternary rather than binary, which itself is a WTF. Then on top of that, the hash function they replaced the broken one with is a wrapping of SHA3 (Keccak) with ternary. So again, they rolled their own crypto, although in a (hopefully!) more minor way. Unfortunately, doing review is a lot of hard work - I know the people involved and they had to waste time and money talking to lawye…

[deleted]

Re: Cryptographic vulnerabilities in IOTA

#45

Earlier quoted context omitted.

Is there a reliable exchange offering reliable short contracts?

IOTA is traded on Bitfinex, which I think allows shorting, although I've never done it. One thing to keep in mind though is that the market is not particularly rational, so even though I think IOTA is doomed in the long term, in the short term it could go up, because markets. So if you do decide to short, make sure to figure out what degree of leverage is important, and what your appetite for risk is.

[deleted]

Re: Cryptographic vulnerabilities in IOTA

#46

IOTA is trash for this and other reasons. You should short it. Issues: 1. Double spends are devastating and easy, since they permanently split the tangle. 2. With no transaction limit, syncing from the beginning of time will take forever. 3. With no transaction limit, keeping up with network traffic will be impossible. (Especially on IoT devices. 4a. Nobody is going to use power and die space on IoT devices for the P…

This guy is spreading lies.

1: Flat out lie, this has never happened. Prove it otherwise.

2: IOTA uses snapshotting, you don't need to sync from the "beginning"

3: Untrue

4: Untrue

5: The only thing so far you've said that's true

6: Untrue

Re: Cryptographic vulnerabilities in IOTA

#47
post #28

Earlier quoted context omitted.

The ZCash team is pretty serious: https://z.cash/team.html

To a higher degree, one should note the Monero Research Lab is leaps and bounds ahead of ZCash.

If you're going to make a bold claim, maybe back it up with some evidence?

Re: Cryptographic vulnerabilities in IOTA

#48

IOTA is trash for this and other reasons. You should short it. Issues: 1. Double spends are devastating and easy, since they permanently split the tangle. 2. With no transaction limit, syncing from the beginning of time will take forever. 3. With no transaction limit, keeping up with network traffic will be impossible. (Especially on IoT devices. 4a. Nobody is going to use power and die space on IoT devices for the P…

This guy is spreading lies. 1: Flat out lie, this has never happened. Prove it otherwise. 2: IOTA uses snapshotting, you don't need to sync from the "beginning" 3: Untrue 4: Untrue 5: The only thing so far you've said that's true 6: Untrue

You'll need better arguments than "untrue", especially when at a glance, the statement is indeed true...

Re: Cryptographic vulnerabilities in IOTA

#49
What I find disturbing is the rush to modify the subtly balanced mechanisms originally established in Bitcoin of work, reward, and punishment, in order to ensure transparency and integrity in a distributed system.

This includes the subtle features and policies relating to control of the money (coin) supply, growth and hence inflation.

Messing with a time proven recipe is going to result in more and more of these revelations.

Re: Cryptographic vulnerabilities in IOTA

#50

Does anyone know if the IOTA devs ever wrote down a justification for using a hand-rolled hash instead of, like, SHA-256? If so, can you link it in a comment? EDIT: I feel compelled to explicitly say that this was a mind-bogglingly stupid thing to do, and there is almost no way to justify it. I'm just curious what they thought they were accomplishing.

> "I'm just curious what they thought they were accomplishing"

Their motivation is really being able to claim an "improved" and "different" cryptocurrency to an audience of promoters, investors and speculators.

Post reply on HN