Live data from Hacker News

IOTA Surges Past Ripple

blocksyn.com

71–80 of 171 posts

Re: IOTA Surges Past Ripple

#71
post #5

IOTA is kind of a joke IMHO: * They have this thing called the "coordinator" which is a master-node run by them, which is a single point of failure. The codebase that this node runs is proprietary software. They claim there will be no need for this masternode in the long run but they never say any ETA about when to remove it (which hints that removing it may always expose the security flaws of their network). This me…

It appears their own crypto was already vulnerable. A friend pointed me to this article: https://www.forbes.com/sites/amycastor/2017/09/07/mit-and-bu... He was also concerned that there's no security proof in the whitepaper. To me, it seems like you could feasibly launch an attack with less than a majority of the computing resources.

My understanding is you only need 33% of the hash power at any given time. Since PoW is only done as part of sending transactions, it probably takes less hash power than you'd think to cause problems.

Re: IOTA Surges Past Ripple

#72

Earlier quoted context omitted.

It appears their own crypto was already vulnerable. A friend pointed me to this article: https://www.forbes.com/sites/amycastor/2017/09/07/mit-and-bu... He was also concerned that there's no security proof in the whitepaper. To me, it seems like you could feasibly launch an attack with less than a majority of the computing resources.

So, how come no one has done that?

The closed-source coordinator, presumably.

Re: IOTA Surges Past Ripple

#73
post #71

Earlier quoted context omitted.

It appears their own crypto was already vulnerable. A friend pointed me to this article: https://www.forbes.com/sites/amycastor/2017/09/07/mit-and-bu... He was also concerned that there's no security proof in the whitepaper. To me, it seems like you could feasibly launch an attack with less than a majority of the computing resources.

My understanding is you only need 33% of the hash power at any given time . Since PoW is only done as part of sending transactions, it probably takes less hash power than you'd think to cause problems.

Why does everyone repeat that Byzantine consensus requires maximum 33% of participants to be dishonest?

If messages cannot be forged, then a consensus could make positive progress with even 99% of participants being dishonest.

Re: IOTA Surges Past Ripple

#74
post #39
post #5

IOTA is kind of a joke IMHO: * They have this thing called the "coordinator" which is a master-node run by them, which is a single point of failure. The codebase that this node runs is proprietary software. They claim there will be no need for this masternode in the long run but they never say any ETA about when to remove it (which hints that removing it may always expose the security flaws of their network). This me…

I see this argument against premining all the time, and while I’m not bullish on IOTA, I think it’s worth at least calling out... just because it’s premined doesn’t mean it’s a scam. Most of the time I see this argument from crypto purists that think the only valid currency is evenly distributed. Using XRP as an example (because I’m most familiar with it), Ripple has been nothing about transparent about the supply of…

> just because it’s premined doesn’t mean it’s a scam

Not a scam, but there is a problem with premining. Consider the first 1 million Satoshi's bitcoins, which, albeit unintentional, still qualifies as pre-mining IMO - we don't know who owns them and whether they are spendable, their value is mind-boggling and if any one of them is spent, it can cause a panic.

Re: IOTA Surges Past Ripple

#75
I like that IOTA is taking a non-blockchain approach. Many people might also be inspired by that.

I recently wrote a paper on eliminating double-spending without relying on global consensus. If there are any cryptographers or security researchers in the audience, I would be interested in hearing your analysis / critique.

https://intercoin.org/technical.pdf

Most of it has pretty straightforward elements so the security properties can be more or less proven, but still I want to hear what the major caveats are.

So far I just heard that it's similar to IOTA and there MAY be some attack, but I would love to hear more specific ideas if they jump out at anyone.

https://twitter.com/joelkatz/status/937455420465061888

Re: IOTA Surges Past Ripple

#76
post #17
post #8

Earlier quoted context omitted.

> I've heard they rolled their own crypto. Yes, let that sink. Haven't verified this myself though. They decided it's a good idea to use ternary logic instead of binary logic so they had to write their own cryptographic primitives based on ternary. Here's a good analysis about the security issues: https://medium.com/@neha/cryptographic-vulnerabilities-in-io...

> They decided it's a good idea to use ternary logic instead of binary logic This is the one main thing that keeps me very, very skeptical regarding IOTA (and the coordinator thing, although that may be resolved someday when traffic increases so they can remove it - at least that's what they say). It looks a bit like they had this JINN processor developed which appears to be ternary in nature, but it went nowhere, an…

So much misinformation here. The Jinn project is in active development.

Re: IOTA Surges Past Ripple

#77
post #70
post #11

Earlier quoted context omitted.

> the IOTA developers had written their own hash function, _Curl_ Did...did they intentionally name it curl, so that when you search for "Is curl secure?" you will find articles saying that curl - the widely used library - is secure, in the hope that people will confuse the two? I know that you shouldn't assume malice when it can be explained with incompetence, but combined with some of the other points here, I can't…

It gets better... their "improved" version of "curl"? Kerl. You can't make this shit up.

Kerl is Keccak I.E. SHA-3, the international NSA standard. They called it Kerl for fun in homage of Curl, which is still under active development with the absolute world-leading cryptographers of lightweight cryptography. Curl had to be invented to push LIGHTWEIGHT cryptography which is necessary for the Internet of Things. It's quite astonishing how much misinformation is spread around.

https://blog.iota.org/iota-foundation-hires-cybercrypt-615d2...

Re: IOTA Surges Past Ripple

#78
post #60

IOTA is built by a bunch of technical founders who know enough about blockchain to confuse a lot of non-experts into thinking they are really smart and credible. But you will see very consistently in the cryptocurrency space that the experts refuse to endorse iota, and frequently say strongly negative things about it. They are very effective at selling snake oil, but that's all their blockchain is. The tangle that th…

I do not own IOTA - thought about it some months back but decided against it because I don't fancy doing trades on or supporting Bitfinex.

Another HN user swayed me away from Monero - which I owned a large part of as he told me about scaling issues.

But my question is to your advice about: look to other experts. As someone coming outside the crypto-universe it is kind of hard to distill who the real experts are - so any advice on how to distill/find credible sources of information in this space?

Re: IOTA Surges Past Ripple

#79
post #5

IOTA is kind of a joke IMHO: * They have this thing called the "coordinator" which is a master-node run by them, which is a single point of failure. The codebase that this node runs is proprietary software. They claim there will be no need for this masternode in the long run but they never say any ETA about when to remove it (which hints that removing it may always expose the security flaws of their network). This me…

It appears their own crypto was already vulnerable. A friend pointed me to this article: https://www.forbes.com/sites/amycastor/2017/09/07/mit-and-bu... He was also concerned that there's no security proof in the whitepaper. To me, it seems like you could feasibly launch an attack with less than a majority of the computing resources.

So much misinformation, where to begin. IOTA is using Keccak/SHA-3, then they are developing a new kind of LIGHTWEIGHT cryptographic primitive together with the world leaders of this field

https://blog.iota.org/iota-foundation-hires-cybercrypt-615d2...

Re: IOTA Surges Past Ripple

#80
post #15

I've looked a bit into IOTA over the past weeks because I was trying to understand how it actually works. I still do not fully understand how the Tangle structure actually functions as a process and/or how it solves scalability issues. If someone smarter than me could enlighten me on this, i would be very thankful. As far as I understand, one main difference between IOTA and classic blockchains is that there are no e…

Any idea what this (https://github.com/iotaledger/ccurl/blob/master/src/lib/curl...) is for in their c implementation?
Post reply on HN