Cryptographers Urge People to Abandon IOTA After Leaked Emails
spectrum.ieee.org
spectrum.ieee.org
I feel like the nerd in class that hopes that the teacher (regulatory bodies) will pinch those bullies so we can get back to topic. I hate that feeling.
from Sapiens: https://books.google.com/books/about/Sapiens.html?id=FmyBAwA...
Definitely in my top ten list. The text is life-changing.
His position, distilled: if people are stupid enough to give me money, who am I to say no?
I suggested his easy money might not be so easy if (for US investors) the SEC, FTC, CFTC, etc. crack down and claw back investor money. Maybe that's fine if you've become hugely profitable in that time, but if you haven't...
Perhaps I'm just an old fool.
EDIT : Just to say I've ensured my email is in my bio now.
This category is broader than you imagine and now includes unsophisticated individuals who can't tell the difference between the blockchain and a bike chain. Lately, I've been hearing a lot of "invest in bitcoin" talk from people who are not well-informed, and do not know what they are gambling on. What's illegal for penny stocks should be equally illegal for cryptocurrency - the Feds should crack the whip.
I can understand the need for the SEC to protect investors when it comes to investment into traditional companies - regular people can't read a 10k and don't sit in on analyst calls that are mandated for public companies registered with the SEC. But if you're investing in an unregulated, highly risky asset, where you don't understand any of the assets or technology the company owns...come on man.
A lot of people are about to find out that cryptocurrencies are, in fact, regulated. It's weird to see some techies agree with the idea that "pedestrian thing, on a computer" patents are invalid (because the "on a computer" bit is irrelevant), but when it comes to "fraud/misrepresentation on a computer", then it suddenly needs to be legally special-cased as somehow different. Intangible/abstracted assets predate cryptocurrencies - there's nothing new about crypto in the eyes of the law.
A counter argument I saw first on Hacker News and then in real life approximates “decentralised currencies make it impossible for governments to enforce laws.” (Obviously wrong, shockingly so, but appears to be a meme in the crypto community.)
These idiots don't realize they're the ones begging the regulators to crush their dreams and bury them in paperwork, fines, fees, and red tape.
Same goes for the crypto space these days. It was sad to watch in tech 20 years ago, and sad to watch now.
I think Bruce Schneier's take was particularly prescient: "In 2017, leaving your crypto algorithm vulnerable to differential cryptanalysis is a rookie mistake. It says that no one of any calibre analyzed their system, and that the odds that their fix makes the system secure is low."
The question is, though, is this going to make a difference to the people playing? Very little about the crypto space makes any sense. It's in a lot of ways just a database but harder -- so much harder -- because the community insists nobody can be trusted. In reality there are very few situations in which you really can't trust one other entity.
Here’s a though exercise: if all the cryptocurrency communities call out research as paid shilling FUD, are we morally obliged to exploit weaknesses and attempt to demonstrate flaws with actual real collateral damage?
The problem with exploiting vulnerabilities for personal gain is that you're hurting more innocent investors, too. It's kinda like carpet bombing, in that you'll accomplish your goal of killing the enemy, but you're taking a lot of other people with them because they have a spurious link.
OTOH, maybe you can gain enough influence to make changes that would marginalize or punish the corrupt operators. A lot of these quasi-cryptos have a hidden layer to prevent this (Ripple, IOTA, etc.). Their coins are more like unregulated stock in the founder's company than a decentralized machine. I'm not sure if that makes them more or less susceptible to a single, strong outside force. They could simply delete your coins, but without knowing the exploit that's just temporary. You would have an actual target (other than 'the system'), which you could pressure (aka blackmail), but they could cash out immediately and walk away.
If I was running a scamcoin (and a terrible person) I'd probably bring the exploit finder into the inner circle to gain positive media (with the associated price bump), wait for the first major act of the new person and then cash out, step down, and disclose the vulnerability. Spin it as the new person trying to cover up problems they caused or improperly addressing the original problem and preventing a good solution.
To counter that, the exploit finder could condition their involvement on releasing the hidden layer's source as a matter of transparency, but really be working on a way to fork without the hidden layer or replace it with a democratized layer. Now you can claim the founders were greedy and didn't want to fix the exploit, and that your working solution was rejected because it took away their ability to manipulate the market. Turn it into an announcement of the new 'fixed' coin.
It'd be a fun movie plot, but probably terribly boring to watch.
As someone fascinated by the technology in the crypto space but very skeptical about the real-world usefulness of many of these projects, I wish I had a better forum to read beside the odd HN post.
Someone should train an AI to detect shilling and use it in the comment ranking algorithm of a forum. Of course they'd probably release a whitepaper and do an ICO.
Both of those are highly representative of the demographic that want to discuss such things on reddit. Others are often even moderated against from some of what I've seen and thus discouraged from discussion. I don't know about that specific sub-reddit, but it certainly happens in some. It's an important echo chamber for exuberant hype so people have a vested interest in protecting that in the mostly unregulated market.
It's not just IOTA. It's more or less any of the top 10 / 20 (by MarketCap) Crypto-currencies on the respective sub-reddits. It's especially bad on r/Ripple where anything critical of Ripple / XRP is instantly deleted by the mods in the name of F.U.D (Fear, Uncertainity, Doubt), and even a small +ve news is posted several times in a day, even trials of Ripple that doesn't even use XRP for the transactions.
And then there was this self-proclaimed shill who described in great detail how he made tons of money shilling various coins on reddit. https://www.reddit.com/r/CryptoCurrency/comments/7xkm0z/i_wa...
From what I've observed on r/Cryptocurrency and related coin subs on reddit over the past month or two, Reddit is being carefully manipulated by whales and scam coin creators to attract bag holders and manipulate the markets for a quick profit. And many of the mods engage in circle-jerk postings, maybe they are in on it too. Who knows.
https://www.amazon.com/Influence-Psychology-Persuasion-Busin...
People will often act against their own best interests to do so.
The chaos is one of the most interesting factors for me. It reminds me of the internet circa 1995 - you have to do your own research, estimate/predict larger trends in information flow, and have a finely tuned bs meter. The biggest barrier to entry is that no one is trustworthy, so even your tools need to be properly vetted or self-made because unlike the 90s internet, the thrill of finding a vulnerability may carry a substantial reward.
I do think there is a legitimate opportunity in the crypto space and 'believe' in the underlying tech. You just have to ignore all the folks building their rockets out of lead and toilet paper while rofling about their moonshot, sneak past the whales, and slip between the trading bots.
One other interesting aspect I don't hear mentioned often is how this comes on the heels of the Russian election meddling and the similarities in tactics. If crypto has any real immediate use for the average person, it's a good way to gauge how susceptible you are to propaganda. Invest (enough to sting if you lose it all) and see if you can turn a profit. Force yourself to put part of that money into an obvious scamcoin and keep track of how you relate to discussions surrounding it. Crypto can be a psychological playground if you let it.
[1] https://meta.stackexchange.com/questions/271576/stack-exchan...
That's just not true at all. Why are you even going after Ripple?
Here's the archive link http://archive.is/vvwl5 to his post that @chrononaut here located.
I know most of Hackernews hates Ethereum, but I really like Ethereum and their ideals, although I am mostly anti ICO. I'd prefer most of these DAPP ideas to be using ETH and not yet another token.
Like Bosch using IOTA to build smart cities in China?
The reddit shill story I linked to is also showing as [REMOVED], but someone in this thread found the archive.is link for that shill story and posted it in this thread.
Here it is. http://archive.is/vvwl5
It does? I admit I'm pretty ignorant of the nuances of all the little alt coins, but I know Ethereum has something to do with distributed applications, with a VM, and I've always thought that cool in the abstract. (though I have no idea what I'd do with it.)
Just probing for information, not trying to have any "tone", do you know what the distaste for Ethereum is rooted in?
https://news.ycombinator.com/item?id=14810008
It is still not entirely clear to me how much of these things are problems with Solidity (name of said language) only, or if any of those issues are core to the Ethereum Virtual Machine (EVM) itself.
I remain hopeful that other languages targeting the EVM will bring to fruition the full potential of Ethereum in a safer manner.
https://medium.com/@Hibryda/why-solidity-isnt-solid-3341af77...
Also some people dislike the fact that Ethereum is executing every program for every message on every blockchain node. I agree that it would be better if it didn’t have to do so but I don’t know how it could be avoided in a distributed trustless system.
https://www.multichain.com/blog/2015/11/smart-contracts-good...
The quality of discourse on /r/iota takes the cake though: https://www.reddit.com/r/Iota/comments/80p3lg/cryptographers... The comments keep going... boy, those iota people really hate zcash!
Also, I completely agree with your fascination and skepticism, but have nothing to add but that agreement.
Why not both?
Most of those crypto currencies smell like MLM schemes for people who scoff at housewives doing the same with physical products. Get rich fast at the expense of the late comers, you can do it! Start by getting your family and friends in it.
The old goals of making a decentralized money to fuel revolutions disappeared fast once the only users ended being pure criminals.
They are utterly useless echo chambers filled with trolls otherwise.
As with basically every cryptocurrency (or technology, for that matter) related sub on reddit, the answer is both.
IOTA team swapped their in-house hash algorithm "Curl" for their new in-house hash algorithm "Kerl" in https://github.com/iotaledger/iri/commit/539e413352a77b1db20... , while at the same day blogging about it and claiming their new in-house hash algorithm is actually SHA-3: https://blog.iota.org/upgrades-updates-d12145e381eb
> "Therefore we have made the simple decision to temporarily switch Curl with Keccak (SHA-3) for cryptographic signing in IOTA."
Just watching this all unfold is making me realize how toxic parts of the cryptocurrency community is and it's making me really sad.
Hopefully what exists in several years time will be good technology, and hopefully the scams have gone away.
I'd wager than marvels like Bitcoin and Ethereum will still be here.
Classy. Not only do they keep their cryptocoin proprietary, they did use a proprietary hash function too.
I wanted to predict the inevitable fall of the currency but realized that the enterprise might just turn into a bank. If they are the gatekeepers to every transaction, they are already sort of a bank. An unregulated bank. With their own bank notes.
Problems arise when someone thinks they should now turn this invention into a money-cow or label it "proprietary magic" (under the pretext of protecting IP/copyright).
Because crypto is really hard and you can't prove your new algorithm is secure. Only after being a popular high value target for years can you have much trust in your new hash. Even SHA2 might have flaws nobody knows about - that's the main purpose behind having SHA3 standardised - as a backup.¹
If you are not the designer of the algorithm it's even worse, because an exploit could be put in intentionally by proper choice of constants which are in some cases undetectable.
[1] https://security.stackexchange.com/questions/152360/should-w...
The market today isn't controlled by engineering or common sense but by whoever shouts the loudest. And once people/companies commit to a certain technology (ideologically and/or financially) it'll be even harder to convince them of them betting on the wrong horse. Why bother with any solid (expensive) engineering practices when you can just raise money based on a whitepaper, entice the first investors by pointing to a hoard of shills all backing your warez, then use the noise generated by ICO promises to ward off any critics. So all you need to do is make your tech political and you can get away with anything thanks to the noise.
Rolling their own broken crypto wasn't the only problem that made infosec community get outraged. Bypassing peer-review processes and then threatening with litigation and insulting researchers ("Hi Neha, are you drunk?") was all part of why nobody wants to touch them with a 10ft pole now. The worst of it is that none of this will stop IOTA from continuing on this road and they'll just play the same game that Trump plays with his hardcore supporter base. Forget about arguing with technical arguments because they'll just wear you down as the discussion with Matthew Green has shown. When their lead engineer thinks that a hash function doesn't have to be collision resistant then there is simply no point in wasting your time trying to make them see the problem (they won't)
And even more baffling that their flagship partner Bosch does not seem to have problem with this practice.
"transactions in IOTA are 10KB (in contrast, Bitcoin transactions are on average 600B)" [1]
https://medium.com/@neha/cryptographic-vulnerabilities-in-io...
Great idea, just a little too early for massive adoption.
Also kind of amusing seeing the different sides of the IOTA team: Sergey is antagonistic and difficult to communicate while David tries to smooth things out and get everyone to play along nicely.
It's a great example of why you need to start from sound foundations.
Then you find out about the curl issue. The unnecessary ternary. Read the white paper and all issues with tip selection was "solved" with hand waving. Then you find out it doesn't even have a client that works on a typical IoT device... Reading the email chain made it ultimately clear: these people have no idea what they're doing. They just threw a bunch of random ultra cool sounding tech together ("post-quantum crypto", of course) and started hyping, while the code never worked. Obvious scam.
What I witnessed after reading through all those letters is a common clash I see over and over of two types of cryptanalysts: Those whose knowledge grew in resource expansive environments (internet/cpu space) and those whose knowledge grew in resource constrictive space (e.g. satellite broadcasting). In particular they clash on the idea that there can ever be a valid use case for a less-than perfect security schema, so-as-to provide certain desired resource benefits, while still being sufficiently secure for a specific use case.
Cryptographers dance around who has perfect security at heart, never getting down to the issue: that they disagree on necessary trade-offs. By the time they do get to it, one will disengage entirely from conversation and assume the other is just stupid. That has happened here (both sides I think). It's a common outcome.
(Disclosures: I worked as a software+hardware reverse engineer, not cryptographer, in the satellite TV space. So I'm not anything close to an authority on the topic but was around these debates often.)
Dealing with and accepting loss is actually quite difficult....
"Intermediate summary of Heilman et al. claims about the security of a previous version of IOTA signature scheme"
https://medium.com/@comefrombeyond/intermediate-summary-of-h...
After all, there are code samples available today which demonstrate the SPECTRE and MELTDOWN attacks.
“Hey, your house door is unlocked.”
“What are you talking about? I left it unlocked on purpose, but it is safe, I wired the metal handle to the power plug, nobody bad can get in.”
“What about the good ones?”
“I installed a Coordinator™ that calls me when you ring, and I can open the door remotely.”
“Wait, didn’t you make this house with the promise that everyone with the key could use it?”
“… well, I don’t see you finding a vulnerability!”
¹ though there are several actual code vulns that have been dismissed by the IOTA team as "FUD" and even threatening researchers with litigation https://prizz.github.io/iota-transaction-spammer-webapp/
You don't need code to prove that a vulnerability exists, it is sufficient, especially for crypto primitives like hash functions or cipher rounds, that there is a mathematical vulnerability that can be potentially exploited.
And to be honest they may be right. Because crypto offers instant liquidity, unlike in venture the people who are going to make the most money aren't necessarily going to be the best at picking the winners.
He says:
> If you want a postcard summary of why you should avoid the Iota project — with your brains and your money — this conversation is it.
but if you read the conversation he's referencing, he doesn't come off as reasonable in it either.
In contrast, the IOTA team members Sergey and David have no idea what they are talking about. The IOTA constructions were broken, and instead of understanding that, they made bogus points and tried to attack the four DCI researchers in various ways.
In that context, I think Green's tweet represented a bit of frustration at the way public rhetoric is being misused.
[1] http://www.tangleblog.com/wp-content/uploads/2018/02/letters...