Live data from Hacker News

Email exchange between MIT Media Lab and the IOTA Foundation [pdf]

tangleblog.com

111–120 of 162 posts

Re: Email exchange between MIT Media Lab and the IOTA Foundation [pdf]

#111

Earlier quoted context omitted.

One priceless line from Ethan Heilman to support that observation: Probably best not to use informal stackoverflow answers and Wikipedia for understanding the security of your system. Yowza.

Are you sober? hahahaha fuck me, this is good stuff.

Obviously Sergey isn't mean, but it's just unfortunate phrasing, because he is a non-native speaker, learning English from Java documentation, right? ;-)

Neha's "I'm going to stop responding now." should have come much earlier.

Re: Email exchange between MIT Media Lab and the IOTA Foundation [pdf]

#113

Earlier quoted context omitted.

back when something awful and metafilter were comparatively big, much of the impetus for the paywalls they put on registrations was to structurally prevent the possibility of this sort of thing. worked fine, although those two communities themselves are pretty moribund. it would all be solved forever and anon with a paywall. 5 mao men, botheads, shilling, you would raise the cost to them by orders of magnitude (steal…

The problem isn’t “bots”. It’s the moderators of these forums. You’ll always find a core group of people willing to believe almost any scam, but putting them on a forum where critical discussion is banned by the moderators is where things go wrong.

Ask your Questions here: https://iota.stackexchange.com/

Re: Email exchange between MIT Media Lab and the IOTA Foundation [pdf]

#114

I can't believe I read that entire train wreck front to back. If IOTA published this to "expose" MIT, it does quite the opposite. Rule number one, all together now, don't roll your own crypto.

It actually worked. People who are clueless about cryptography (i.e. like 99% of crypto investors) are totally on IOTA side here. Invancheglo is a grade A troll.

Re: Email exchange between MIT Media Lab and the IOTA Foundation [pdf]

#115
post #44

Interesting to see the range of opinions about IOTA. The conclusions on HN are (so far) completely at odds from those on the cryptocurrency subreddit: https://www.reddit.com/r/CryptoCurrency/comments/7zztey/full... Meanwhile the commercial world seems happy to engage with IOTA: "Volkswagen CDO will join the supervisory board of the IOTA foundation. And now, Volkswagen is going to utilise this technology in their auto…

What's funny is that crypto issues are actually not the biggest problem with IOTA.

The biggest problem is that it just makes no sense. It's not going to be decentralized & secure at the same time. It's LESS efficient than blockchain in every way. It's bad for IoT. It doesn't have any of fancy features like Ethereum.

Crypto issues is just an icing on a cake. They can change crypto functions, but they can't change the fact that coin is the worst choice for IoT (or pretty much anything).

The only selling point is that it's fee-less. But it's possible to make a centralized fee-less coin which would be much more secure and useful than IOTA.

Re: Email exchange between MIT Media Lab and the IOTA Foundation [pdf]

#116

> I have a feeling that you refuse to accept existence of cryptographic protocols not mentioned in the textbooks read by you. That is a cringe worthy statement by someone doing a cryptographic decentralized project. The whole conversation is a trainwreck. :/

The best part is that part of their argument for why it's not a real vulnerability is that the coordinator might have rejected it - except that the coordinator is essentially a server run by them, which makes the entire "crypto" part of crypto currency totally unnecessary.

Seems to me the hash function should just be H(x) = 0. Very efficient, just as secure!

Re: Email exchange between MIT Media Lab and the IOTA Foundation [pdf]

#117
IOTA: Can you look into our laundry detergent product and review it's safety? DCI: Sure. We've got some accomplished chemists that will do a careful review. IOTA: Cool, let us know what you find. DCI: Uh oh, it looks like we found a critical problem with your detergent. We tested the product and it seems to have poisonous properties. IOTA: How did that happen? Did someone accidentally ingest it? DCI: Can you prove that your laundry detergent pods are safe when ingested? IOTA: Don't ingest them. Use them to do laundry. DCI: I see, so you don't deny that they are unsafe for consumption? IOTA: I don't understand. Why would you try to eat them? Our instructions clearly say that's not what they are for. DCI: Look, we have a lot of experience with chemicals. Every chemist out there will tell you that these ingredients are unsafe for consumption. Ask for a second opinion if you like. IOTA: Ok but can you show that they are unsafe to use for laundry? DCI: We'll let everyone know that this laundry detergent is unsafe. IOTA: Wait, can you also tell everyone that they shouldn't eat them? DCI: ... IOTA: Did you just publish?

Re: Email exchange between MIT Media Lab and the IOTA Foundation [pdf]

#118
eikons https://www.reddit.com/r/CryptoCurrency/comments/7zztey/full...

IOTA: Can you look into our laundry detergent product and review it's safety? DCI: Sure. We've got some accomplished chemists that will do a careful review. IOTA: Cool, let us know what you find. DCI: Uh oh, it looks like we found a critical problem with your detergent. We tested the product and it seems to have poisonous properties. IOTA: How did that happen? Did someone accidentally ingest it? DCI: Can you prove that your laundry detergent pods are safe when ingested? IOTA: Don't ingest them. Use them to do laundry. DCI: I see, so you don't deny that they are unsafe for consumption? IOTA: I don't understand. Why would you try to eat them? Our instructions clearly say that's not what they are for. DCI: Look, we have a lot of experience with chemicals. Every chemist out there will tell you that these ingredients are unsafe for consumption. Ask for a second opinion if you like. IOTA: Ok but can you show that they are unsafe to use for laundry? DCI: We'll let everyone know that this laundry detergent is unsafe. IOTA: Wait, can you also tell everyone that they shouldn't eat them? DCI: ... IOTA: Did you just publish?

Re: Email exchange between MIT Media Lab and the IOTA Foundation [pdf]

#119

Without reading reams of stuff over my head, why is this interesting?

IOTA rolled their own crypto. As they were warned by many in and out of the crypto (in both senses of the word) communities at the time, it was susceptible to attack. MIT Media Lab wrote a responsible disclosure report on a vulnerability. IOTA kept pushing back the publication date, based on a mixture of amateur cryptography arguments and nitpicking over disclosure issues. MIT Media Lab finally published, well after…

>MIT Media Lab wrote a responsible disclosure report

Pardon my ignorance but I am confused with engagement of MIT Media lab in this. Was it volunteer or there was some formal engagement between IOTA foundation and MIT Media lab?

Re: Email exchange between MIT Media Lab and the IOTA Foundation [pdf]

#120
post #82

As a participant in the SHA hash function contest who broke one of the 51 Round-1 SHA-3 proposals and who worked on security proofs for another SHA-3 proposal I can say with some authority that using the sponge construction and showing statistical properties of the transformation function is not sufficient to ensure security. Of the 51 Round-1 SHA-3 proposals all of them passed statistical tests and at least one roun…

That’s because other fields of computer science can either prove or demonstrate that their solution works. Cryptography almost never has solid proofs, and demonstrations prove nothing. When you’re working on something where “works great” and “completely broken” are almost indistinguishable, the only way to even have a hope of avoiding the second one is by having a lot of smart people bang on it for a long time.

What? Modern cryptography is based on proofs and definitions. Sure, we can't prove that SHA2 is cryptographically-strong (that imply P≠NP), but we can show that it resists certain kinds of attacks.

Furthermore, assuming certain properties are satisfied by SHA2, we can order that different constructions based on it (eg a Merkle tree) are secure.

Cryptography is highly mathematical.

Post reply on HN