Live data from Hacker News

Cryptographic vulnerabilities in IOTA

medium.com

51–60 of 73 posts

Re: Cryptographic vulnerabilities in IOTA

#51
post #39

Does anyone know if the IOTA devs ever wrote down a justification for using a hand-rolled hash instead of, like, SHA-256? If so, can you link it in a comment? EDIT: I feel compelled to explicitly say that this was a mind-bogglingly stupid thing to do, and there is almost no way to justify it. I'm just curious what they thought they were accomplishing.

The justification can be found on the Reddit: "Because we needed an efficient hash function for IoT and the future of ternary computing (memristors, spintronics, optical computing and the trend in Artificial Neural Networks) This has been known since before we even began the project. I spoke with the Keccak team about this all the way back in early 2015 before a code of IOTA was written" Source: https://gyazo.com/03c…

Easily the most buzzword-laden BS I have ever laid my eyes on. I'm surprised the word "quantum" isn't in there too.

Re: Cryptographic vulnerabilities in IOTA

#52

Earlier quoted context omitted.

The IOTA devs are deluded. Here's there justification: "Creating a new cryptographic hash function is no trivial undertaking, even when it is being built on preexisting world class standards. “Don’t roll your own crypto” is a compulsory uttered mantra that serves as a good guiding principle for 99.9% of projects, but there are exceptions to the rule. When spearheading technology for a new paradigm this statement is n…

"Or, sometimes, back."

But always twirling, twirling, twirling towards freedom!

Re: Cryptographic vulnerabilities in IOTA

#53

IOTA is trash for this and other reasons. You should short it. Issues: 1. Double spends are devastating and easy, since they permanently split the tangle. 2. With no transaction limit, syncing from the beginning of time will take forever. 3. With no transaction limit, keeping up with network traffic will be impossible. (Especially on IoT devices. 4a. Nobody is going to use power and die space on IoT devices for the P…

This guy is spreading lies. 1: Flat out lie, this has never happened. Prove it otherwise. 2: IOTA uses snapshotting, you don't need to sync from the "beginning" 3: Untrue 4: Untrue 5: The only thing so far you've said that's true 6: Untrue

This guy owns IOTA

Re: Cryptographic vulnerabilities in IOTA

#54
post #39

Earlier quoted context omitted.

The justification can be found on the Reddit: "Because we needed an efficient hash function for IoT and the future of ternary computing (memristors, spintronics, optical computing and the trend in Artificial Neural Networks) This has been known since before we even began the project. I spoke with the Keccak team about this all the way back in early 2015 before a code of IOTA was written" Source: https://gyazo.com/03c…

Easily the most buzzword-laden BS I have ever laid my eyes on. I'm surprised the word "quantum" isn't in there too.

Iota talks about quantum quite a bit, including with regards to their choice of ternary

Re: Cryptographic vulnerabilities in IOTA

#55
This paints a pretty bad picture for IOTA. Ternany, custom hash functions, and a significant amount of buzzwords used to back up their poorly made choices. It's interesting their market cap is still as high as it is, although that's cryptocurrencies for you.

IOTA is down around 10% in the last 24 hours, leaving it with the worst daily performance out of the top ~45 coins (https://coinmarketcap.com/). I wonder if the authors short sold it :)

Re: Cryptographic vulnerabilities in IOTA

#56
post #3
post #2

> “In 2017, leaving your crypto algorithm vulnerable to differential cryptanalysis is a rookie mistake. It says that no one of any calibre analyzed their system, and that the odds that their fix makes the system secure is low,” states Bruce Schneier, renowned security technologist, about IOTA when we shared our attack. Indeed

Moreover, rolling their own hash function (which is what they did) is a rookie mistake.

I wonder how many rookies there are in this super-hot field.

Re: Cryptographic vulnerabilities in IOTA

#57
post #28
post #14

The thing that I think should really worry you is that the reaction among the professional cryptographers to this (or at least the dozens I talk to on Slack and Twitter) is "well, that's cryptocurrency for you". If you have the impression that serious cryptographers are knee deep in the problem space of trying to make sure cryptocurrencies are actually secure, revise your expectations.

The ZCash team is pretty serious: https://z.cash/team.html

The ZCash team are one of the most academic teams out there (for cryptocurrencies), which is a very good thing. The more serious cryptographers that get involved in cryptocurrency the better.

Re: Cryptographic vulnerabilities in IOTA

#58
post #38

Earlier quoted context omitted.

To a higher degree, one should note the Monero Research Lab is leaps and bounds ahead of ZCash.

I'm not competent to compare the work, but there don't appear to be any professional academic cryptographers on either the core or research lab teams. https://getmonero.org/resources/people.html Whereas the ZCash team includes several people who were well-known cryptographers before ZCash came along.

Of course there are. All members of MRL are professional academic cryptographers. There's Surae, Sarang, Shen, etc. Meanwhile the background and "academic" activities of most of the academics behind Zcash are quite sketchy despite their fame. People will come to see this before long.

Re: Cryptographic vulnerabilities in IOTA

#59
post #14

The thing that I think should really worry you is that the reaction among the professional cryptographers to this (or at least the dozens I talk to on Slack and Twitter) is "well, that's cryptocurrency for you". If you have the impression that serious cryptographers are knee deep in the problem space of trying to make sure cryptocurrencies are actually secure, revise your expectations.

> If you have the impression that serious cryptographers are knee deep in the problem space of trying to make sure cryptocurrencies are actually secure, revise your expectations.

I'd say the teams behind Bitcoin core, Ethereum and especially Zcash can hold their weight to a certain extent.

It's still very early days though and there is a lot more serious research that needs to be done.

I'm not saying that they are perfect, some of those teams have made mistakes, but it's still a cutting edge field so it will take time for more experts to get involved.

Re: Cryptographic vulnerabilities in IOTA

#60
post #14

The thing that I think should really worry you is that the reaction among the professional cryptographers to this (or at least the dozens I talk to on Slack and Twitter) is "well, that's cryptocurrency for you". If you have the impression that serious cryptographers are knee deep in the problem space of trying to make sure cryptocurrencies are actually secure, revise your expectations.

> If you have the impression that serious cryptographers are knee deep in the problem space of trying to make sure cryptocurrencies are actually secure, revise your expectations. Confidence in cryptocurrencies come from their ability to be patched. Every death knell observation merely makes them stronger. People understood that in 2011 and acquired cryptocurrency, they understand that in 2017 and acquire cryptocurren…

The fact that people are buying cryptocurrency is not in itself evidence that cryptocurrency is cryptographically secure. Paying actual cryptographers to help create your cryptocurrency is evidence that it's cryptographically secure.

People use software that lies about how secure it is all the time - even when money is on the line - because they're not qualified to understand security, and additionally don't have the understanding of how to delegate that job of understanding. I'm interested in IOTA, but I've yet to see a respected security company put out a document that explains why it's secure and where potential weaknesses that we might be able to exploit in 5, 10, 20 years might be hiding, so I'm not touching it with a bargepole.

Put it this way: would you use a bank that didn't employ any security engineers and yet made grand statements about how secure its processes are?

Post reply on HN