Live data from Hacker News

Why I find IOTA alarming

medium.com

61–70 of 130 posts

Re: Why I find IOTA alarming

#61

Earlier quoted context omitted.

> Actual deep cryptography such as cipher design is an area where truly extreme and very esoteric expertise is required to even get started I hear this every time cryptography is brought up. I think I get that it's hard, but people make it sound like it's the hardest thing ever . Where does this extreme complexity stem from? And what's the field of knowledge required? (Mathematics I imagine)

I think the problem is that it's tricky math, and there are so many possible subtle failure modes that make a scheme insecure (e.g., timing attacks). So in order to have a chance of making a new secure scheme, you should be an expert in crpyotgraphy (i.e., be very familiar with past schemes, why they worked, and common ways schemes fail that are non-obvious to someone without such a background). Furthermore, given th…

> I think the problem is that it's tricky math

Tricky maths and just-as-tricky implementation. And a broken implementation can obviously make the best maths worthless.

Re: Why I find IOTA alarming

#62
post #49
post #19

Earlier quoted context omitted.

"Swarm Intelligence" - Okay, I stopped there. Can't throw something like that out without a link or commentary. Getting a decentralized swarm to implement transaction processing is highly non-trivial, especially when (as the OP highlights) incentives are delicate and the entire system must be extremely secure.

Especially true since parallelizing the processing of transactions is orders of magnitude easier than parallelizing STORAGE of transactions in decentralized systems- he's deflecting the criticism towards an easier problem.

... which is the opposite of what a good engineer does. A good engineer focuses first on the hardest aspects of the problem, and tends to guide discussion there.

Re: Why I find IOTA alarming

#63
post #11

Earlier quoted context omitted.

1. The vulnrability existed in their active codebase and network - only AFTER the research team contacted IOTA with the working exploit did they shut the entire (centralized) network down to patch the code. “In 2017, leaving your crypto algorithm vulnerable to differential cryptanalysis is a rookie mistake. It says that no one of any calibre analyzed their system, and that the odds that their fix makes the system sec…

1) In order for the attack to succeed, the attacker would have to have access to the seed at which point the entire thing becomes moot. 2) The android wallet has seed generation. So it's not a question of "refusal", more a question of priotities. Seedgen had not been a priority of the team. We can argue if its good or bad but at the end of the day, it is what it is. Creating a seed is not hard and if you can't put in…

1. The attack the MIT team developed on IOTA was a way to efficiently brute force wallet key combos to forge transactions of funds.

2. Every other cryptocurrency has implemented the seed generator as it's the most basic and fundamental feature necessary for this type of software. It's so trivial to implement, it really begs the question of why the IOTA team didn't just include it in all their software releases.

3. The comment CEO David Sønstebø was directly replying to was just commenting on how confusing the software is compared to other cryptocurrency wallets:

  I know it sounds simple newb mistake, but even me I 
  probably would have made that mistake and having been 
  using crypto for a while.

  So to sum it up don't use same receive address in IOTA. 
  I'll try to burn that in the back of my brain.
To add insult to injury regarding the OP who lost $30,000, it sure sounded like David was indirectly referencing that users loss with his response to the above comment

  "Price to pay for quantum security :) " - David Sønstebø, IOTA CEO

Re: Why I find IOTA alarming

#64
post #36

Earlier quoted context omitted.

Even the double spending problem is not really resolved. Just with the current theft, there are recipes posted[1] on how to recover the stolen IOTA by basically enforcing the double spending and trying to give your spending a higher priority than the fraudulent transactions had. That means fraudulent transaction could try this themselves and just need to exploit that race condition. That means a fraud needs to someho…

You're conflating a lot of things here. Racing a fraudulent transaction to have a legitimate one confirm faster is not a double spend, like at all. Up until the moment one of the transactions confirms, no funds have changed hands. What you're also conflating is the fact that the hash collision has no influence on transacting funds in the first place. The DCI report recently released their vulnerability exploiting cod…

Is not a race a way to delay individual transactions and essentially an DOS for targeted members of the network?

Re: Why I find IOTA alarming

#65
post #2

I feel like I'm missing one side of the story. I don't know much about IOTA but from what I learned reading articles linked on HN today IOTA: - Uses custom "ternary" crypto which has been shown to have vulnerabilities in the past. - Has software that doesn't include the basic function of generating wallet addresses, instead having some users rely on shady 3rd party websites and getting their coins stolen. - Does away…

The fact that it is using balanced Ternary makes it seem like the science project of young/inexperienced developers. If you're building a cryptocurrency put away your hubris and use what is tried-and-true.

From their Learning IOTA FAQ:

What makes IOTA quantum-secure?

IOTA uses hash-based signatures (https://www.imperialviolet.org/2013/07/18/hashsig.html) instead of elliptic curve cryptography (ECC). Not only is hash-based signatures a lot faster than ECC, but it also greatly simplifies the overall protocol (signing and verification). What actually makes IOTA quantum-secure is the fact that we use Winternitz signatures. IOTA's ternary hash function is called Curl.)[1]

Curl is designed by Genetic Algorithm. I wonder how they could test this? Did they 'do the math'?

[1] https://learn.iota.org/faq/what-makes-iota-quantum-secure

Re: Why I find IOTA alarming

#66
post #32
post #2

I feel like I'm missing one side of the story. I don't know much about IOTA but from what I learned reading articles linked on HN today IOTA: - Uses custom "ternary" crypto which has been shown to have vulnerabilities in the past. - Has software that doesn't include the basic function of generating wallet addresses, instead having some users rely on shady 3rd party websites and getting their coins stolen. - Does away…

The fun part is, that if you want to discuss such details (and I have much more) with an IOTA enthusiast, I get thinks like "I don't understand the technical details, but the founders say so you must be wrong. You are just discredit me." So you, how want to discuss the details when people are just convinced without having knowledge themselves?

Belief is real.

Re: Why I find IOTA alarming

#67
post #2

I feel like I'm missing one side of the story. I don't know much about IOTA but from what I learned reading articles linked on HN today IOTA: - Uses custom "ternary" crypto which has been shown to have vulnerabilities in the past. - Has software that doesn't include the basic function of generating wallet addresses, instead having some users rely on shady 3rd party websites and getting their coins stolen. - Does away…

1) No, the whole implementation of the ledger is written in ternary. Its current hasing function is called Kerl. The vulnerability that DCI claimed existed is impossible to be used in the wild because an attacker would have to have seed level access to the wallet at which point, any attack vector becomes moot.

2) The IOTA Foundation and the community expressly warned not to trust unaffiliated sites. Saying they relied on them is just shady. Would we hang TBL for inventing email because people had their money stolen by nigerian scammers? No, because shifting blame on the man would be even more stupid than wiring thousands of dollars to someone you don't know. Seedgeneration is, in this current non-feature-complete implementation simply not a priority. Creating a seed is not hard and if you can't muck one up, nobody is forcing anyone to try and feed their greed trying to "enter at the ground floor, lambo lol!!!" using IOTA. I would wait for a wallet implementation that comes with a generator.

3) IOTA is very very young by far not feature complete. Hanging it out to dry because it isn't yet isn't exactly fair. Everything had to start somewhere. Though, with all that in mind, it still works rather well in my experience and it scales. It solves a lot of problems inherent with blockchain and it has a future market goal it wants to service. The rest is speculation. As always, I guess.

Re: Why I find IOTA alarming

#68
post #14
post #2

I feel like I'm missing one side of the story. I don't know much about IOTA but from what I learned reading articles linked on HN today IOTA: - Uses custom "ternary" crypto which has been shown to have vulnerabilities in the past. - Has software that doesn't include the basic function of generating wallet addresses, instead having some users rely on shady 3rd party websites and getting their coins stolen. - Does away…

Custom crypto primitives (ciphers, hashes, etc.) is a big red flag to me unless the designers are cryptographers. I know a fair bit about crypto. I would implement (and have implemented) higher order constructions like encrypted and authenticated protocols according to design patterns and principles put forward by competent cryptographers. I would never ever even attempt to design a cipher or a cryptographically stro…

The designer for Curl was a Genetic Algorithm.

Re: Why I find IOTA alarming

#69
post #40

Earlier quoted context omitted.

Cryptos lend themselves to flamewars, no twitter or anything else needed. You have a bunch of people who are trying to get rich quick while on average not understanding much about the underlying technology. Try to have a technical discussion on any crypto enthusiast forum and see how well it goes. In my experience it turns really ugly really quickly. In general I give up after I get the first "you don't know what you…

We all rise together, so we should more encouraging of one another’s endeavors in crypto and blockchain There’s your tip-off for a scam: don’t ask questions, and be encouraging to each other, because it’s us against a skeptical world. Cults, penny stocks, Amway, and now crypto currency scams apparently: I’ve observed similar patterns in all. Not that we shouldn’t support each other in our mutual endeavors, but if tha…

> growing food crops for fuel is energy net positive, and otherwise a good idea.

According to Wikipedia (https://en.wikipedia.org/wiki/Ethanol_fuel_energy_balance), growing sugarcane for ethanol is 8x net energy positive.

Re: Why I find IOTA alarming

#70
post #2

I feel like I'm missing one side of the story. I don't know much about IOTA but from what I learned reading articles linked on HN today IOTA: - Uses custom "ternary" crypto which has been shown to have vulnerabilities in the past. - Has software that doesn't include the basic function of generating wallet addresses, instead having some users rely on shady 3rd party websites and getting their coins stolen. - Does away…

This[1] is a recent (yesterday) interview with David Sønstebø founder of IOTA. He addresses the points you are mentioning.

[1] https://www.youtube.com/watch?v=GwhJQ67zxbg

Post reply on HN