"Intermediate summary of Heilman et al. claims about the security of a previous version of IOTA signature scheme"
https://medium.com/@comefrombeyond/intermediate-summary-of-h...
"Intermediate summary of Heilman et al. claims about the security of a previous version of IOTA signature scheme"
https://medium.com/@comefrombeyond/intermediate-summary-of-h...
After all, there are code samples available today which demonstrate the SPECTRE and MELTDOWN attacks.
You don't need code to prove that a vulnerability exists, it is sufficient, especially for crypto primitives like hash functions or cipher rounds, that there is a mathematical vulnerability that can be potentially exploited.
“Hey, your house door is unlocked.”
“What are you talking about? I left it unlocked on purpose, but it is safe, I wired the metal handle to the power plug, nobody bad can get in.”
“What about the good ones?”
“I installed a Coordinator™ that calls me when you ring, and I can open the door remotely.”
“Wait, didn’t you make this house with the promise that everyone with the key could use it?”
“… well, I don’t see you finding a vulnerability!”
¹ though there are several actual code vulns that have been dismissed by the IOTA team as "FUD" and even threatening researchers with litigation https://prizz.github.io/iota-transaction-spammer-webapp/