I feel like I'm missing one side of the story. I don't know much about IOTA but from what I learned reading articles linked on HN today IOTA: - Uses custom "ternary" crypto which has been shown to have vulnerabilities in the past. - Has software that doesn't include the basic function of generating wallet addresses, instead having some users rely on shady 3rd party websites and getting their coins stolen. - Does away…
1. There have been no vulnerabilities in the past. Please read: https://blog.iota.org/official-iota-foundation-response-to-t... 2. If people are unable to generate a simple seed (password) on their own. How can they even begin to understand cryptocurrency or even new tech based on IoT? Still, yes it should be in the wallet and it will be added, but only for investors, I guess?! 3. Please read the following from their…
“In 2017, leaving your crypto algorithm vulnerable to
differential cryptanalysis is a rookie mistake. It says
that no one of any calibre analyzed their system, and that
the odds that their fix makes the system secure is low,”
Bruce Schneier, renowned security technologist,
about IOTA when we shared our attack.
We discovered a vulnerability in IOTA after reviewing
their code on GitHub in July. We disclosed what we found
to the IOTA team on July 14th, and have been in contact
with them since then as we discovered new issues and
exploits. IOTA issued a patch that addresses the
vulnerabilities we found on August 7th. IOTA no longer has
the vulnerabilities we found, they have been fixed. To
learn more about the details of our attack, you can view
the full disclosure and review our attack examples.
https://github.com/mit-dci/tangled-curl/blob/master/vuln-iot...https://github.com/mit-dci/tangled-curl
2. If every other cryptocurrency software team can impliment seed generation in their wallet software, why does IOTA refuse to?
3. Please read this comment from the CEO of IOTA, David Sønstebø on why he doesn't care if you lose money using IOTA: https://reddit.com/r/CryptoCurrency/comments/7gwl38/hello_gu...