How a malicious seed generation website stole $4M
thatoddmailbox.github.io
thatoddmailbox.github.io
https://medium.com/@neha/cryptographic-vulnerabilities-in-io...
The CEO of IOTA David Sonstebo tells his users it's not his problem if they lose money using IOTA because they're too dumb to understand the design flaws: https://np.reddit.com/r/CryptoCurrency/comments/7gwl38/hello...
Yikes.
IOTA also relies on a centralized sever owned and operated by David Sonstebo which takes periodic snapshots so transactions can be rolled back if the IOTA devs ever feel the want to. https://domschiener.gitbooks.io/iota-guide/content/chapter1/...
Further reading:
Nick Johnson: Why I Find IOTA Deeply Alarming https://hackernoon.com/why-i-find-iota-deeply-alarming-934f1...
Daniel Rice: Why I Also Find IOTA Deeply Alarming https://medium.com/@thedrbits/why-i-also-find-iota-deeply-al...
Eric Wall: IOTA Is Centralized https://medium.com/@ercwl/iota-is-centralized-6289246e7b4d
Sidenote the founding developer of IOTA, Sergey Ivancheglo claims to have built a time machine http://come-from-beyond.com/about-me/
> In 2017, leaving your crypto algorithm vulnerable to differential cryptanalysis is a rookie mistake. It says that no one of any calibre analyzed their system, and that the odds that their fix makes the system secure is low — Bruce Schneier (about IOTA)
OK, it looks like the answer is they designed a custom hash function because their system is built with ternary logic (?!?):
https://hackernoon.com/why-i-find-iota-deeply-alarming-934f1...
... because "Ternary is the optimal radix" according to their cofounder:
> Ternary is the optimal radix, actually Base E (2.71....) is, but you can't make processors like that. So it comes down to Base Binary (2) vs Base Ternary (3). 3 is closer to the universal optimum 2.71 than is 2. That is the absolute most simple elevator pitch for ternary.
https://iota.stackexchange.com/questions/8/why-does-iota-use...
Reading about the design of this system, I feel like I just entered the twilight zone, or maybe the website for Time Cube. Urbit makes more sense than this. (The design of Urbit makes fine sense, it's just the implementation is extremely obscure.)
..
> It's covered in GUI FAQ, take time to read.
- /u/DavidSonstebo (CEO of IOTA)
Wow.
Anyone who has ever built software knows that users rarely read FAQs (maybe 1-5%). Anyone who's ever made ANY product/service/contract knows most users don't read the fine print.
I'm not sure if he's one of those hardcore backend guys who are oblivious to how humans use software, or maybe a bit autistic in his expectations of other people's capabilities/worldview, or is highly arrogant (rolling your own crypto fits this category well), or simply doesn't care because "everyone else is just not as smart as me". But regardless of the whys, that's simply no excuse in 2018 for pushing out very serious software, with real users, and significant time/money being potentially lost due to a complete disregard for real-life UX/UI.
> IOTA was made for machines, not humans.
This is no excuse either, it's a predictable expectation that new users will come in with their own preconceived understanding of how cryptocurrencies work - informed by how nearly every other currency works. So if your currency functions significantly different it's on the creator to communicate those differences clearly to the users.
Expecting tools to work without reading the manual reminds me of
"Pray, Mr. Babbage, if you put into the machine wrong figures, will the right answers come out?" In one case a member of the Upper, and in the other a member of the Lower, House put this question. I am not able rightly to apprehend the kind of confusion of ideas that could provoke such a question."
If the user WON'T read the FAQ, then the FAQ shouldn't exist. So how to educate an illiterate user?
How modest. That guy needs help.
Your sidenote linking to http://come-from-beyond.com/about-me/ and claiming that it's not a satirical website is comical.
More importantly, IOTA never implemented seed generation into their native client software. With this being THE central function to their entire platform, one has to question the priorities and motives of the team behind this project.
When coupled with the comments by the CEO, one has to ask if the negligence is so absurdly severe it's malicious?
[1] https://blog.iota.org/official-iota-foundation-response-to-t...
[2] https://iotasupport.com/gui-newseed.shtml
[3] https://iota.guide/seed/how-to-generate-iota-wallet-seed/
Every other cryptocurrency software can facilitate wallet generation seeds natively, why does IOTA refuse to implement it?
I'm simply providing historical facts. Your bias as an invested speculator is clear. https://news.ycombinator.com/item?id=15634175
The response to the IOTA hash flaw has a followup from MIT as well:
https://www.media.mit.edu/posts/iota-response/
On Friday, MIT Technology Review published an article on
the cryptocurrency IOTA. The headline stated that the
currency “could outperform Bitcoin.” However, we here at
the MIT Media Lab have issues with the story.
Specifically, my colleagues in the Digital Currency
Initiative (DCI) recently uncovered a gaping hole in
IOTA’s software. And while that flaw has now been patched,
we certainly disagree with reporter Michael Orcutt’s
assertion that IOTA is “secure.” As the Director of the
MIT Media Lab, I felt it important we outline our specific
concerns.
— Joi*
Quote One: “The rally began in late November, after the IOTA
Foundation, the German nonprofit behind the novel
cryptocurrency, announced that it was teaming up with
several major technology firms to develop a ‘decentralized
data marketplace.’” The article goes on to say: “And the
high-profile names participating in its data market pilot—
including Microsoft, Deutsche Telekom, and Fujitsu—suggest
IOTA is onto something.”
Response One: IOTA’s relationships with top-tier companies continue to
be nebulous.
In the Technology Review article, Orcutt linked to a
November 28, 2017 blog post from IOTA that gave the
perception that Microsoft was a partner in the
marketplace. However, after a flurry of media reports
making this claim, IOTA corrected their relationship
status with top-tier companies like Microsoft, Cisco, and
Huawei in a blog post dated December 16. That the MIT Tech
Review story links to IOTA’s initial blog post instead of
the later version is misleading.
Quote Two: Though IOTA tokens can be used like any other
cryptocurrency, the protocol was designed specifically for
use on connected devices, says cofounder David Sønstebø.
Organizations collect huge amounts of data from these
gadgets, from weather tracking systems to sensors that
monitor the performance of industrial machinery (a.k.a.
the Internet of things). But nearly all of that
information is wasted, sitting in siloed databases and not
making money for its owners, says Sønstebø.
IOTA’s system can address this in two ways, he says.
First, it can assure the integrity of this data by
securing it in a tamper-proof decentralized ledger.
Response Two: Whether or not IOTA’s ledger is “tamper-proof,” the entire
IOTA network went down in November, and was completely
inoperable for about three days. That this has never
happened in Bitcoin or Ethereum suggests the extent to
which the IOTA network relies on the “coordinator”—a
single point of failure—and is not truly decentralized.
Also troubling, IOTA developers were able to transfer
funds out of users’ IOTA accounts. The user was then
required to participate in a “reclaim” process to request
their funds. We believe IOTA’s developers should not have
access to such funds; it’s rife with risk.
Quote Three: Second, it enables fee-less transactions between the
owners of the data and anyone who wants to buy it—and
there are plenty of companies that want to get their hands
on data.
Now, here’s where things get really interesting. Instead
of a blockchain, IOTA uses a “tangle,” which is based on a
mathematical concept called a directed acyclic graph.
Sønstebø says his team pursued an alternative approach
after deciding that blockchains are too costly—it has
recently cost as much as $20 per Bitcoin transaction
because of high demand—and inefficient to operate at the
scale required for the Internet of things.
Response Three: Orcutt’s claim that IOTA is free of fees is misleading.
Though perhaps not immediately obvious, IOTA transactions
are "zero fee" in exactly the same way that Bitcoin
transactions are. An important difference is that Bitcoin
has miners who can perform the proof of work for you,
while IOTA users do the proof of work on their own
devices, per transaction. However, a Bitcoin user can also
mine their own block to get their transactions accepted
into the blockchain without paying fees. To put it another
way, most people wouldn’t be interested in buying a
refrigerator operated by a hand crank, even if the
advertisement said “No electricity required!”
It’s true that transactions with Bitcoin and other digital
currencies, even when amortized over a block with
thousands of other transactions, require much more work
than transactions in IOTA. However, the claim is not that
IOTA transactions are easier—the claim appears to be that
IOTA transactions are free.
Semantics aside, this claim, which appears in IOTA
marketing materials, is deceptive; the work required is a
fee, whether or not it requires a monetary payment.
Restricting the ways in which the fee can be
paid—requiring that the work be done on a user’s own
device—doesn’t make it go away.
Quote Four: “In August, researchers from MIT and Boston University
reported that they discovered a “serious vulnerability” in
a novel cryptographic technique IOTA was using. IOTA has
patched the vulnerability, and Sønstebø says that security
measures in place would have prevented anyone from losing
funds. The foundation has hired a third-party firm to help
it continue to develop the technique, which Sønstebø says
represents the kind of “lightweight cryptography” needed
for low-power connected devices, like sensors.”
Response Four: Once the Digital Currency Initiative published the break
in IOTA’s curl hash function, its author, Sergey
Ivancheglo, offered two conflicting explanations for the
vulnerability.
The first explanation was that the flaw was
intentional—that it was meant to serve as a form of “copy
protection.” If anyone used this code in their own work,
he said, the IOTA developers would be able to exploit the
flaw and damage other systems that were using the hash
function. However, later, he offered a conflicting
explanation that he didn’t write the curl at all, but that
an AI wrote it.
We do not find either of these explanations convincing,
even in isolation. That they contradict each other makes
them even less so.It's still surprising that it was a fraud, it looked like a legit website. It seems almost too blatant a crime given that the Github repo, IPs and the domain name of the site can probably be traced to someone.
I'm getting General Ripper vibes over here...
But that piece of code should've triggered red flags even if the hacker didn't add a payload to overwrite Math.seedrandom to always use the same seed. The fact that https://github.com/davidbau/seedrandom isn't cryptographically secure should've been enough to turn you away and warn other. And if you read it a bit more you'll notice that it is mostly junk code (unused variables like visitedHash, newindex).
Props to the hacker for the method acting. From the commit log https://github.com/eggdroid/eggseed3/commits/master I would not have suspect any malicious intent and just attribute it to incompetence (which might've worked better underhanded-c-contest style instead of using an explicit backdoor).
This for me points out the issue with cryptocurrency in general. Even someone with technical prowess can't figure out how exactly things are supposed to work.
The author is a high school student who has written very basic HTML/CSS and some C projects, including one as a joke. This is not to say all HS students can't figure out how to use Bitcoin, but you might be overselling the experience/aptitude of the author in order to make a biased point against cryptocurrency.
They do seem to have at least some degree of technical proficiency, and their error isn't exactly obvious to me either. (I make no claims about my aptitude, only that I'm old.)
This kind of pre-generated seed hack is quite dangerous, a lot of mobile apps, don't have deterministic build so you can't be sure the open source version is the same as the one from apple store, and I bet Apple won't do such a thoroughly search.
With that said, I would like to believe that if caught, these types of seed hacks could be prosecuted. (If viable)
The GNU Taler project might be interesting to you, then.
It is based on design decisions that are refreshingly different from classic crypto currencies (who implement more an anarcho-capitalism mindset). Because of those design differences, I'm not sure if it should be considered a crypto currency or not. (They themselves do not.)
Website: https://gnutaler.org/
Presentation at SHA2017: https://taler.net/videos/sha2017taler.webm
(Too bad I can't edit my original comment anymore here on HN. I find it disgusting to have helped spread a scam website and not being able to fix that afterwards.)
I don't care that I can make a quick buck by preying on people's FOMO, the whole movement is fueled by seemingly emotional, albeit baseless, arguments and bravado.
It's not so much because authorities don't consider it a crime, like stealing WoW gear, but because of the difficulties in investigating and prosecuting the case vs the total losses.
Actually, I do lean towards the notion that stealing/embezzling/defrauding iotas/bitcoins/cuervocoins is legally equivalent to looting gold in WoW.
I see nothing in this news/thread today about "Iota" (which I have never heard of until today) that makes me consider it serious, legal business.
It approaches the seriousness of WoW from below.
I assume the seed is used to generate a public key for some kind of wallet? Is IOTA some kind of cryptocurrency?
The project doesn't currently come with it's own seed generator so users are left using (sometimes) shady third-party services, such as this website.
The developers insist that it's not a currency intended for 'speculation between users' but rather for a particular machine-to-machine usecase, which is how they attempt to dodge lots of the criticism regarding the flaws in both the crypto and UX.
https://blog.trezor.io/trezor-integration-with-myetherwallet...
Basically, unless you're 100% vigilant literally all of the time, you're in trouble. This is just one reason why we invented banks, to centralize risk and mitigation.
https://github.com/moustachio-belvedere/iotaseedgen/blob/mas...
Edit: spelling and added words
It's a Web Worker not a Service Worker. Just to be stubborn
The latest wallet doesn't allow you to send money to such an address.