Live data from Hacker News

Email exchange between MIT Media Lab and the IOTA Foundation [pdf]

tangleblog.com

21–30 of 162 posts

Re: Email exchange between MIT Media Lab and the IOTA Foundation [pdf]

#21
>2. If the IOTA project wishes to ensure that trinary logic is involved in the proof of work and signature hashing process we suggest that a trinary function could be composed with a secure hash algorithm in a construction such as: >Hash(msg) = MD6(msg || TrinaryFunction(msg)).

Haha this is a wonderful suggestion. "If you weirdos think ternary arithmetic has any benefits, just combine it with a crypto primitive you didn't handroll, ya dingus"

And then they say it's okay because of "higher level checks" that a colliding transaction wouldn't validate, so then when one is demonstrated, they say "it's okay because we'd just decide to reject the bad one even if the hash is the same" and the final defense is "something something distributed ledgers Satoshi"

Re: Email exchange between MIT Media Lab and the IOTA Foundation [pdf]

#22
> Hey Ethan, Did you receive the invite? We can also setup a chat with our ex-NSA post-Quantum hash function experts after we get the initial confusion out of the way. Best, David

It is a great example of someone (the "expert") convincing a non-technical person that they are the "ninja rockstar 11x post-quantum hash function expert".

I've seen this many times. Managers / owners don't have ability to assess who is an expert and who isn't. So whoever talks more convincingly is the "ninja rockstar". After that they can do no wrong. Also after that somehow admitting publicly that the person they picked is a scam artist becomes pretty hard, because it also means admitting to their own mistake of believing them.

Others who see what's going on, leave and this this eventually leads to the whole ship sinking.

Oh and accusations of drunkenness of course, those are always so constructive and helpful.

Re: Email exchange between MIT Media Lab and the IOTA Foundation [pdf]

#23
I only got to page 30 before moving on, but this line is telling:

> In this case you are right, second-preimage resistance is an anti-feature, collision resistance threat is nullified by Coordinator while allows us to easily attack scam-driven copycats. (pg. 24)

The Coordinator referenced is a validation node ran by the IOTA team which currently processes all transactions.

Re: Email exchange between MIT Media Lab and the IOTA Foundation [pdf]

#24
post #23

I only got to page 30 before moving on, but this line is telling: > In this case you are right, second-preimage resistance is an anti-feature, collision resistance threat is nullified by Coordinator while allows us to easily attack scam-driven copycats. (pg. 24) The Coordinator referenced is a validation node ran by the IOTA team which currently processes all transactions.

Telling of what? The paper makes a simple claim that because collision-resistance is broken, their custom signature scheme is broken

Re: Email exchange between MIT Media Lab and the IOTA Foundation [pdf]

#25
post #12
post #8

Earlier quoted context omitted.

The "second" in "second preimage" doesn't refer to hashing something twice. It means that you already have one preimage for a hash (presumably because you started with the "preimage" and calculated the hash from that), and you want to find a second, different one.

In simpler terms, given H(x), it is impossible to find x’ such that H(x’) == H(x) in polynomial time.

To be pedantic: given x and H(x), it is impossible to find x’ such that H(x’) == H(x) in a practical amount of time.

(You need x, and an attack doesn't need to be polynomial to break the hash function; it just needs to be fast enough, considering constant factors, to fit within some plausible attacker's computational resources.)

Re: Email exchange between MIT Media Lab and the IOTA Foundation [pdf]

#27
post #17
post #14

Earlier quoted context omitted.

Because IOTA is rekt, it has been for some time, and this is just what you should expect from people who try to roll their own cryptography, then get defensive when a notable real cryptographer points out flaws.

Agreed. FD: I've 'shorted' IOTA in any way possible, mostly through altcoins which may actually deliver on IOTAs promises. As soon as I heard they were using ternary as some kind of competitive advantage, I lost all faith in them.

Totally. And not to sound holier than thou, I'm guilty of "unnecessary re-implementation" possibly more than most. I use my own window manager, have written my own high performance disk archival compression, wrote my own (super)multichannel (>8) lossless audio format, am working on my own large sequence data (think: DNA) native clustering algorithm....

But for the love of god man, /never invent your own crypto/

Re: Email exchange between MIT Media Lab and the IOTA Foundation [pdf]

#28
post #17

Earlier quoted context omitted.

Agreed. FD: I've 'shorted' IOTA in any way possible, mostly through altcoins which may actually deliver on IOTAs promises. As soon as I heard they were using ternary as some kind of competitive advantage, I lost all faith in them.

somehow they claim ternery is easier to implement in hardware when it's strictly false in every way.

I have a vague memory of once upon a time reading a paper alleging that if you could start everything over again from the beginning, that somehow ternary was more efficient than binary for a digital architecture, something having to do with power usage. But other than that it just sounds like nonsense.

Re: Email exchange between MIT Media Lab and the IOTA Foundation [pdf]

#29
post #27
post #17

Earlier quoted context omitted.

Agreed. FD: I've 'shorted' IOTA in any way possible, mostly through altcoins which may actually deliver on IOTAs promises. As soon as I heard they were using ternary as some kind of competitive advantage, I lost all faith in them.

Totally. And not to sound holier than thou, I'm guilty of "unnecessary re-implementation" possibly more than most. I use my own window manager, have written my own high performance disk archival compression, wrote my own (super)multichannel (>8) lossless audio format, am working on my own large sequence data (think: DNA) native clustering algorithm.... But for the love of god man, /never invent your own crypto/

Also, honest question: Anyone know of any exchange or means to take a short position on IOTA? I only did so though "never buying any".

Re: Email exchange between MIT Media Lab and the IOTA Foundation [pdf]

#30

This is being leaked with the agenda of purporting to show malfeasance from MIT DCI, but if anything shows the opposite, in my opinion.

It makes the IOTA team look like rank amateurs at best, and scam artists at worst.
Post reply on HN