[0] - https://medium.com/@jer979/disclosure-im-an-advisor-to-iota-...
Cryptographic vulnerabilities in IOTA
61–70 of 73 posts
Re: Cryptographic vulnerabilities in IOTA
#62Re: Cryptographic vulnerabilities in IOTA
#63Earlier quoted context omitted.
I'm not competent to compare the work, but there don't appear to be any professional academic cryptographers on either the core or research lab teams. https://getmonero.org/resources/people.html Whereas the ZCash team includes several people who were well-known cryptographers before ZCash came along.
Of course there are. All members of MRL are professional academic cryptographers. There's Surae, Sarang, Shen, etc. Meanwhile the background and "academic" activities of most of the academics behind Zcash are quite sketchy despite their fame. People will come to see this before long.
ZCash has well-known people, employed at places like Johns Hopkins and Berkeley, who specialize in cryptography and have long lists of publications to their names. If anyone is going to be called "sketchy" it should be the people hiding behind pseudonyms.
I don't own ZCash or Monero, so I don't have a dog in this fight except that I get annoyed at the Monero community's strident insistence of their intellectual superiority over ZCash.
Re: Cryptographic vulnerabilities in IOTA
#64Earlier quoted context omitted.
Of course there are. All members of MRL are professional academic cryptographers. There's Surae, Sarang, Shen, etc. Meanwhile the background and "academic" activities of most of the academics behind Zcash are quite sketchy despite their fame. People will come to see this before long.
The bios of those three say they have degrees in mathematical sciences, physics, and algebraic geometry, respectively. None of those are cryptography. On top of that, they're pseudonymous, so we can't even verify these claims. ZCash has well-known people, employed at places like Johns Hopkins and Berkeley, who specialize in cryptography and have long lists of publications to their names. If anyone is going to be call…
And yes i call zcash skechy too, creating a currency with a trusted setup and stuffing 10% off all mining rewards in your pockets its an outright scam.
Re: Cryptographic vulnerabilities in IOTA
#65Earlier quoted context omitted.
So, are you saying that this is not part of the fundamental analysis you should do if you have money at stake? You have made such analysis to argue about the threshold numbers.
Where did I say "this is not part of the fundamental analysis you should do" ? My only point is that >50% attacks by the people involved are purely theoretical. Attacks by almost any state are the end of your project. A billion dollars is enough to DDoS pretty much everything.
Then you argued about the bounds and if they were theoretical or not which was not the central point of the argument and we can choose another issue to illustrate our central point. I think we can argue if it is theoretical or not ad infinitum.
So, to push forward my central argument I will again say: we need to check beyond the cryptography. Not only that, I will tell you: stay tuned because a new security finding with Bitcoin will be published soon.
Re: Cryptographic vulnerabilities in IOTA
#66IOTA is trash for this and other reasons. You should short it. Issues: 1. Double spends are devastating and easy, since they permanently split the tangle. 2. With no transaction limit, syncing from the beginning of time will take forever. 3. With no transaction limit, keeping up with network traffic will be impossible. (Especially on IoT devices. 4a. Nobody is going to use power and die space on IoT devices for the P…
Pretty much every exchange has been hacked at one time or another. Ethereum itself had a vulnerability, and they just forked it. Parity, the ethereum wallet software, had a vulnerability that put millions up for grabs .. the equivalent of a function like 'transferCoin' was made public instead of private.
Re: Cryptographic vulnerabilities in IOTA
#67Earlier quoted context omitted.
The bios of those three say they have degrees in mathematical sciences, physics, and algebraic geometry, respectively. None of those are cryptography. On top of that, they're pseudonymous, so we can't even verify these claims. ZCash has well-known people, employed at places like Johns Hopkins and Berkeley, who specialize in cryptography and have long lists of publications to their names. If anyone is going to be call…
They are not hiding behind pseudonyms and attend meetups regularly, stuff like RingCt was peer revieewed by legder journal... And yes i call zcash skechy too, creating a currency with a trusted setup and stuffing 10% off all mining rewards in your pockets its an outright scam.
Re: Cryptographic vulnerabilities in IOTA
#68Earlier quoted context omitted.
The bios of those three say they have degrees in mathematical sciences, physics, and algebraic geometry, respectively. None of those are cryptography. On top of that, they're pseudonymous, so we can't even verify these claims. ZCash has well-known people, employed at places like Johns Hopkins and Berkeley, who specialize in cryptography and have long lists of publications to their names. If anyone is going to be call…
They are not hiding behind pseudonyms and attend meetups regularly, stuff like RingCt was peer revieewed by legder journal... And yes i call zcash skechy too, creating a currency with a trusted setup and stuffing 10% off all mining rewards in your pockets its an outright scam.
You're derailing.
Re: Cryptographic vulnerabilities in IOTA
#69Does anyone know if the IOTA devs ever wrote down a justification for using a hand-rolled hash instead of, like, SHA-256? If so, can you link it in a comment? EDIT: I feel compelled to explicitly say that this was a mind-bogglingly stupid thing to do, and there is almost no way to justify it. I'm just curious what they thought they were accomplishing.
The IOTA devs are deluded. Here's there justification: "Creating a new cryptographic hash function is no trivial undertaking, even when it is being built on preexisting world class standards. “Don’t roll your own crypto” is a compulsory uttered mantra that serves as a good guiding principle for 99.9% of projects, but there are exceptions to the rule. When spearheading technology for a new paradigm this statement is n…
Re: Cryptographic vulnerabilities in IOTA
#70IOTA is trash for this and other reasons. You should short it. Issues: 1. Double spends are devastating and easy, since they permanently split the tangle. 2. With no transaction limit, syncing from the beginning of time will take forever. 3. With no transaction limit, keeping up with network traffic will be impossible. (Especially on IoT devices. 4a. Nobody is going to use power and die space on IoT devices for the P…
https://www.reddit.com/r/Iota/comments/6yvpfo/iota_ama_septe...
Most of your points are completely moot.