Disclosure of a Major Bug in CryptoNote Based Currencies
getmonero.org
getmonero.org
Ouch. I guess we're now seeing the value in having a crypto-currency depend on as few (well-tested) cryptographic primitives as possible.
It always strikes me as a bit overzealous when blockchain-based currencies add exotic cryptographic primitives to improve on the properties of Bitcoin a little bit, while at the same time risking complete destruction in case just the tiniest detail has gone unnoticed.
I feel like crypto-money must rely on cryptographic primitives whose subversion would cause great harm elsewhere, too. If not, the financial incentive to expose flaws isn't present until it's already too late (the currency is very valuable). If this isn't the case, the crypto-currency becomes a somewhat meaningless research project, as the financial incentive to reveal weaknesses just isn't there.
There's no simple conservative path you can chart through this particular crypto use case that will make things easy. Public key cryptography is difficult and dangerous.
What bothers me is that none of them are using high-assurance software methods. Cryptocurrencies are better than most in that the developers have an informal security model written down somewhere. However, the real specification boils down to a pile of C++ code.
This ridiculous premise is the reality right now.
Also, the calculations are by no means worthless. They prevent alteration of the blockchain history. Without this, everyone involved in a crypto-currency can collude to increase their own balances without leaving any proof whatsoever. It's not waste; it's a necessity.
Imagine an attacker exploiting a bug in the reference implementation, where the exploit is able to travel from node to node (not far-fetched). This exploit deletes the existing chain that all nodes carry, replacing it with the attacker's version. With Bitcoin this exploit has no effect, because proof-of-work makes the chain immutable. For non-proof-of-work currencies, everyone will be left wondering which version of the history is the correct one, and the only way to settle the matter would be through trust.
I'll edit the post.
Poloniex should suspend the trading of ByteCoin until it can be determined whether or not the bug has been exploited, as some reports indicate:
https://www.reddit.com/r/Monero/comments/6buu5j/disclosure_o...
It's surprising that an exchange like Poloniex would allow trading in potentially fradulent ByteCoins to continue.
https://poloniex.com/exchange#btc_bcn
However, in Poloniex's defense, they could argue that the security disclosure just 24 hours ago has not given them enough time to respond, and that up until now they were only ever aware of a (fake) DoS bug impacting CryptoNote coins, rather than a critical vulnerability.
https://getmonero.org/2017/05/17/disclosure-of-a-major-bug-i...
2017-02-21: The patch is surreptitiously snuck into the Monero codebase in pull request #1744. It is kept secret to prevent it being used to attack other CryptoNote coins.
2017-02-22: A point release of Monero is rushed out so that exchanges and mining pools can update, under the guise of it preventing a RingCT DoS attack (such attack did not exist, but it seemed a fair explanation).
https://webcache.googleusercontent.com/search?q=cache:https:...
It's inherently problematic because you need to somehow get your users to upgrade their software without knowledge of exactly why they need to do this.
I know Bitcoin has had denial-of-service fixes sneaked in, but I'm not aware of anything of this nature.
One thing's for sure: the commit logs of crypto-currencies will be scrutinized a lot more by black hats from now on.
This is the de-facto route for closed-source software, but Linus doesn't mark all security patches as such [0]. There are a lot of unpatched systems out there and Linus doesn't have the time to parse the exact ramifications of every security bug.
That being said, it's pretty clear that we need to invest in more robust software development methods.
In case of the Bitcoin overflow bug[1], a public announcement was made and everyone was asked to upgrade.
What, because of vulnerabilities? How are anonymous cryptocurrencies any different from literally any other piece of software in this regard?
There have been incidents of 'accidental inflation' of fully-anonymous cryptocurrencies (as opposed to 'semi-anonymous' [sender/receiver anonymous] and pseudonymous bitcoin).
Zerocoin had a 1/4 inflation from https://news.ycombinator.com/item?id=13672117
I wouldn't go so far as to say this is will prevent this technology from ever being secure. Its early days. Don't play with what you can't lose.
The great monero team did notify other CryptoNote based currencies, it seems that the granddaddy Bytecoin didn't fix it before the notification period. There is no evidence that they exploited this. They even came up with a method for detecting if it had been exploited...
Can you really trust Ethereum as a platform given the DAO debacle? I do, but only because I seriously doubt there will ever be a massive hardfork like that again.
"The die has been cast"