Cryptographic vulnerabilities in IOTA
medium.com
medium.com
If you have the impression that serious cryptographers are knee deep in the problem space of trying to make sure cryptocurrencies are actually secure, revise your expectations.
https://getmonero.org/resources/people.html
Whereas the ZCash team includes several people who were well-known cryptographers before ZCash came along.
ZCash has well-known people, employed at places like Johns Hopkins and Berkeley, who specialize in cryptography and have long lists of publications to their names. If anyone is going to be called "sketchy" it should be the people hiding behind pseudonyms.
I don't own ZCash or Monero, so I don't have a dog in this fight except that I get annoyed at the Monero community's strident insistence of their intellectual superiority over ZCash.
And yes i call zcash skechy too, creating a currency with a trusted setup and stuffing 10% off all mining rewards in your pockets its an outright scam.
You're derailing.
Confidence in cryptocurrencies come from their ability to be patched.
Every death knell observation merely makes them stronger. People understood that in 2011 and acquired cryptocurrency, they understand that in 2017 and acquire cryptocurrency, they would prefer widespread self perpetuating ignorance continues while they acquire cryptocurrency.
People use software that lies about how secure it is all the time - even when money is on the line - because they're not qualified to understand security, and additionally don't have the understanding of how to delegate that job of understanding. I'm interested in IOTA, but I've yet to see a respected security company put out a document that explains why it's secure and where potential weaknesses that we might be able to exploit in 5, 10, 20 years might be hiding, so I'm not touching it with a bargepole.
Put it this way: would you use a bank that didn't employ any security engineers and yet made grand statements about how secure its processes are?
Lots of cryptographers hate cryptocurrencies, lots of them don't. Alessandro Chiesa is being Zcash for example.
I'd say the teams behind Bitcoin core, Ethereum and especially Zcash can hold their weight to a certain extent.
It's still very early days though and there is a lot more serious research that needs to be done.
I'm not saying that they are perfect, some of those teams have made mistakes, but it's still a cutting edge field so it will take time for more experts to get involved.
For example, Bitcoin is perfect from the cryptographic perspective but its security threshold is around 33% [1]. Last year we also started a spreadsheet to benchmark different cryptocurrency metrics [2] but the blockchain/cryptocurrency/ICO space outpaced this initiative ;-).
[1] https://arxiv.org/abs/1311.0243
[2] https://docs.google.com/spreadsheets/d/1DQ770nGnHfJOoRSqTLmI...
My only point is that >50% attacks by the people involved are purely theoretical. Attacks by almost any state are the end of your project. A billion dollars is enough to DDoS pretty much everything.
Then you argued about the bounds and if they were theoretical or not which was not the central point of the argument and we can choose another issue to illustrate our central point. I think we can argue if it is theoretical or not ad infinitum.
So, to push forward my central argument I will again say: we need to check beyond the cryptography. Not only that, I will tell you: stay tuned because a new security finding with Bitcoin will be published soon.
https://blog.iota.org/curl-disclosure-beyond-the-headline-18...
[0] - https://medium.com/@jer979/disclosure-im-an-advisor-to-iota-...
EDIT: I feel compelled to explicitly say that this was a mind-bogglingly stupid thing to do, and there is almost no way to justify it. I'm just curious what they thought they were accomplishing.
"Creating a new cryptographic hash function is no trivial undertaking, even when it is being built on preexisting world class standards. “Don’t roll your own crypto” is a compulsory uttered mantra that serves as a good guiding principle for 99.9% of projects, but there are exceptions to the rule. When spearheading technology for a new paradigm this statement is no longer axiomatic. Progress must march on."
"Because we needed an efficient hash function for IoT and the future of ternary computing (memristors, spintronics, optical computing and the trend in Artificial Neural Networks)
This has been known since before we even began the project. I spoke with the Keccak team about this all the way back in early 2015 before a code of IOTA was written"
Their motivation is really being able to claim an "improved" and "different" cryptocurrency to an audience of promoters, investors and speculators.
1. Double spends are devastating and easy, since they permanently split the tangle.
2. With no transaction limit, syncing from the beginning of time will take forever.
3. With no transaction limit, keeping up with network traffic will be impossible. (Especially on IoT devices.
4a. Nobody is going to use power and die space on IoT devices for the PoW chip.
4b. Or, alternately, if, as they claim, the PoW chip will take very little die space and very little power, the network will be destroyed outright by non-IoT PoW chips spamming the network.
5. There is currently a coordinator which confirms transactions. It is not P2P. If they remove the coordinator, I could write code that destroys the network by issuing TiB of transactions per day, making it impossible to sync/keep up.
6. Mesh networks of the type that they envisage deploying IOTA on are not widely deployed, and it's not clear that they will ever be widely deployed.
7. Tip selection does not converge.
One thing to keep in mind though is that the market is not particularly rational, so even though I think IOTA is doomed in the long term, in the short term it could go up, because markets. So if you do decide to short, make sure to figure out what degree of leverage is important, and what your appetite for risk is.
1: Flat out lie, this has never happened. Prove it otherwise.
2: IOTA uses snapshotting, you don't need to sync from the "beginning"
3: Untrue
4: Untrue
5: The only thing so far you've said that's true
6: Untrue
2. Then by creating new outputs one could make the snapshot arbitrarily large, making it impossible to sync a single snapshot.
3. Why?
4. Why?
5. So you agree there's an unfixable DoS vector?
6. Why?
Pretty much every exchange has been hacked at one time or another. Ethereum itself had a vulnerability, and they just forked it. Parity, the ethereum wallet software, had a vulnerability that put millions up for grabs .. the equivalent of a function like 'transferCoin' was made public instead of private.
https://www.reddit.com/r/Iota/comments/6yvpfo/iota_ama_septe...
Most of your points are completely moot.
IOTA is down around 10% in the last 24 hours, leaving it with the worst daily performance out of the top ~45 coins (https://coinmarketcap.com/). I wonder if the authors short sold it :)
Exhibit A: Don't roll your own crypto...we don't just say it because it's fun.
Kudos to the authors for not weaponizing the vulnerability for profit. There was no sound basis for the developers to design their own hash function, and it was a collosal mistake. It's not as if any of the other hash functions were inadequate for their security or performance needs.
Frankly, I don't know if I should blame ignorance or hubris in this situation.
This includes the subtle features and policies relating to control of the money (coin) supply, growth and hence inflation.
Messing with a time proven recipe is going to result in more and more of these revelations.
Indeed
Then on top of that, the hash function they replaced the broken one with is a wrapping of SHA3 (Keccak) with ternary. So again, they rolled their own crypto, although in a (hopefully!) more minor way.
Unfortunately, doing review is a lot of hard work - I know the people involved and they had to waste time and money talking to lawyers and the like - so it's quite possible we won't find out about the flaws in their "fix" until some hacker exploits them to steal money.
Even relatively small changes to hash functions and using them in non-standard ways often fails to give the security guarantees you expected. For instance, this idea from Russell O'Conner is a good example: https://lists.linuxfoundation.org/pipermail/bitcoin-dev/2017...
His extremely professional handling of the situation is also a good example!