Live data from Hacker News

Cryptographers Urge People to Abandon IOTA After Leaked Emails

spectrum.ieee.org

51–60 of 127 posts

Re: Cryptographers Urge People to Abandon IOTA After Leaked Emails

#51
post #32

Earlier quoted context omitted.

I think that if half of their ideas could actually work and be secure, it would be a good thing. If IOTA was a real thing for example I would happily be apart of that community. Unfortunately it's a total waste of time. I remember avoiding IOTA early on due to the arrogance of the founders, I really didn't like their tune. I know most of Hackernews hates Ethereum, but I really like Ethereum and their ideals, although…

What is a "real thing"? Like Bosch using IOTA to build smart cities in China? https://twitter.com/BoschPresse/status/968479596868980737

Link does not reference IOTA?

Re: Cryptographers Urge People to Abandon IOTA After Leaked Emails

#52
post #50
post #43

> The researchers disclosed to IOTA that the hash function they were using, which was an in-house concotion called Curl, was broken. Classy. Not only do they keep their cryptocoin proprietary, they did use a proprietary hash function too. I wanted to predict the inevitable fall of the currency but realized that the enterprise might just turn into a bank. If they are the gatekeepers to every transaction, they are alre…

Is there any (valid) reason why someone would want to use their own hash function? Secure hash functions, as far as I am aware, are pretty established and widely available and really easy to use..

No. There is no valid reason to do so.

Re: Cryptographers Urge People to Abandon IOTA After Leaked Emails

#53
post #36

It still baffles me that the official response from the IOTA foundation is that the vulnerability was inserted intentionally as copy-protection. And even more baffling that their flagship partner Bosch does not seem to have problem with this practice.

I doubt that any of the decision makers at Bosch have enough theoretical knowledge to be able to form any sort of opinion about it.

Re: Cryptographers Urge People to Abandon IOTA After Leaked Emails

#54
post #28

Earlier quoted context omitted.

Don't worry free market will sort it out eventually. Dump money will run out after a few big project failures. Investors will be more sophisticated. It's a new market and what's happening now is natural, it's the same as dot-com bubble. Smart regulators can help free market to get rid of dishonest projects. But the common problems with regulators is that they are not smart and they are slow to fix their mistakes if t…

Mentioning the "free market" in any other context than a joke will make most people not take your post seriously.

I assume only die hard leftists like you downvoted my comment despite me writing:

> Smart regulators can help free market to get rid of dishonest projects.

I gave you one unrelated example of total stupidity of regulators - H1B visa.

Instead of high salary requirement, it has bachelor degree requirement. Having bachelor degree tells absolutely nothing about qualification of employee. In fact, there are shitload of bachelor degree holders in computer science who don't know difference between O(n) and O(n^2) and have no idea what red-black tree is. H1B is abused badly. Large majority of H1B quota goes to very questionable body shops who flood the market with cheap labor. It can be ended very quickly if high skills determined by size of salary and bonus. Yet for years, regulators still can't figure it out.

Not to mention that while high skilled indians and chinese wait green card for decades, some lucky and completely unskilled people get green card straight away by winning diversity lottery.

There is endless list of stupidity of government.

I'm sure there is a lot of people here in HN who just hate cryptocurrencies and just want to kill the market by government machine.

Re: Cryptographers Urge People to Abandon IOTA After Leaked Emails

#55
After +1 hour reading things start to be surreal.

IOTA team swapped their in-house hash algorithm "Curl" for their new in-house hash algorithm "Kerl" in https://github.com/iotaledger/iri/commit/539e413352a77b1db20... , while at the same day blogging about it and claiming their new in-house hash algorithm is actually SHA-3: https://blog.iota.org/upgrades-updates-d12145e381eb

> "Therefore we have made the simple decision to temporarily switch Curl with Keccak (SHA-3) for cryptographic signing in IOTA."

Re: Cryptographers Urge People to Abandon IOTA After Leaked Emails

#56
post #50
post #43

> The researchers disclosed to IOTA that the hash function they were using, which was an in-house concotion called Curl, was broken. Classy. Not only do they keep their cryptocoin proprietary, they did use a proprietary hash function too. I wanted to predict the inevitable fall of the currency but realized that the enterprise might just turn into a bank. If they are the gatekeepers to every transaction, they are alre…

Is there any (valid) reason why someone would want to use their own hash function? Secure hash functions, as far as I am aware, are pretty established and widely available and really easy to use..

Yes. But it would more likely be the case where they are encrypting the data before hashing it to reduce the chance for a hash collision.

Re: Cryptographers Urge People to Abandon IOTA After Leaked Emails

#57
post #50
post #43

> The researchers disclosed to IOTA that the hash function they were using, which was an in-house concotion called Curl, was broken. Classy. Not only do they keep their cryptocoin proprietary, they did use a proprietary hash function too. I wanted to predict the inevitable fall of the currency but realized that the enterprise might just turn into a bank. If they are the gatekeepers to every transaction, they are alre…

Is there any (valid) reason why someone would want to use their own hash function? Secure hash functions, as far as I am aware, are pretty established and widely available and really easy to use..

that knowledge while widely available within the engineering community isn't a given outside that circle. We're kind of arguing in a bubble. From a marketers pov they can sell it as "revolutionary proprietary PQ-proof, AI resistant and other made up bunch of words", and the masses buy it and don't care about it as long you tell them it's safe.

The market today isn't controlled by engineering or common sense but by whoever shouts the loudest. And once people/companies commit to a certain technology (ideologically and/or financially) it'll be even harder to convince them of them betting on the wrong horse. Why bother with any solid (expensive) engineering practices when you can just raise money based on a whitepaper, entice the first investors by pointing to a hoard of shills all backing your warez, then use the noise generated by ICO promises to ward off any critics. So all you need to do is make your tech political and you can get away with anything thanks to the noise.

Rolling their own broken crypto wasn't the only problem that made infosec community get outraged. Bypassing peer-review processes and then threatening with litigation and insulting researchers ("Hi Neha, are you drunk?") was all part of why nobody wants to touch them with a 10ft pole now. The worst of it is that none of this will stop IOTA from continuing on this road and they'll just play the same game that Trump plays with his hardcore supporter base. Forget about arguing with technical arguments because they'll just wear you down as the discussion with Matthew Green has shown. When their lead engineer thinks that a hash function doesn't have to be collision resistant then there is simply no point in wasting your time trying to make them see the problem (they won't)

Re: Cryptographers Urge People to Abandon IOTA After Leaked Emails

#58
post #38

Earlier quoted context omitted.

What is there even to discuss? The disclosures and email tell me everything I wanted to know.

Where is the code which exploits the supposed vulnerability in IOTA? After all, there are code samples available today which demonstrate the SPECTRE and MELTDOWN attacks.

There are explanations on how it works here [https://archive.is/6imWR] [http://www.tangleblog.com/wp-content/uploads/2018/02/letters...]

You don't need code to prove that a vulnerability exists, it is sufficient, especially for crypto primitives like hash functions or cipher rounds, that there is a mathematical vulnerability that can be potentially exploited.

Re: Cryptographers Urge People to Abandon IOTA After Leaked Emails

#59
post #6

As an aside, is there anyone else extremely disappointed with the quality of discussion over at /r/cryptocurrency? This conflict over IOTA has been unfolding for a long time and the guys on that subreddit defend it fanatically, accusing DCI of "FUD"ing IOTA. I am not sure if the subscriber base is technically illiterate or users that hold a given coin have a strong incentive to dismiss any criticism. As someone fasci…

> This conflict over IOTA has been unfolding for a long time and the guys on that subreddit defend it fanatically, accusing DCI of "FUD"ing IOTA It's not just IOTA. It's more or less any of the top 10 / 20 (by MarketCap) Crypto-currencies on the respective sub-reddits. It's especially bad on r/Ripple where anything critical of Ripple / XRP is instantly deleted by the mods in the name of F.U.D (Fear, Uncertainity, Dou…

Usually you can trust ~50% of the information in popular 'specialty' subreddits, but the crypto subs are straight up useless beyond major headlines. Even then, the discussions are 90%+ trolls and shills and 10% memes. Steem and Bitcoin Forum have been better, but all around the larger problem is that things move so quickly that the information you're looking for is probably no longer accurate.

The chaos is one of the most interesting factors for me. It reminds me of the internet circa 1995 - you have to do your own research, estimate/predict larger trends in information flow, and have a finely tuned bs meter. The biggest barrier to entry is that no one is trustworthy, so even your tools need to be properly vetted or self-made because unlike the 90s internet, the thrill of finding a vulnerability may carry a substantial reward.

I do think there is a legitimate opportunity in the crypto space and 'believe' in the underlying tech. You just have to ignore all the folks building their rockets out of lead and toilet paper while rofling about their moonshot, sneak past the whales, and slip between the trading bots.

One other interesting aspect I don't hear mentioned often is how this comes on the heels of the Russian election meddling and the similarities in tactics. If crypto has any real immediate use for the average person, it's a good way to gauge how susceptible you are to propaganda. Invest (enough to sting if you lose it all) and see if you can turn a profit. Force yourself to put part of that money into an obvious scamcoin and keep track of how you relate to discussions surrounding it. Crypto can be a psychological playground if you let it.

Re: Cryptographers Urge People to Abandon IOTA After Leaked Emails

#60
post #50

Earlier quoted context omitted.

Is there any (valid) reason why someone would want to use their own hash function? Secure hash functions, as far as I am aware, are pretty established and widely available and really easy to use..

No. There is no valid reason to do so.

if you understand the Math and agree that whatever you do needs to go through a proper peer review then why not. Saying "nobody may research the subject because you'll fail" is bad science. If you work in this space, know your Math, and don't rely on your invention to be put into production this year then why not study the problem space and innovate by following the established best practices!?

Problems arise when someone thinks they should now turn this invention into a money-cow or label it "proprietary magic" (under the pretext of protecting IP/copyright).

Post reply on HN