HNHacker News
TopNewBestAskShowJobs

smrtfckr

-5 karma · joined January 29, 2018

submissionscomments
smrtfckr··on Why I find IOTA alarming
1) No, the whole implementation of the ledger is written in ternary. Its current hasing function is called Kerl. The vulnerability that DCI claimed existed is impossible to be used in the wild because an attacker would have to have seed level access to the wallet at which point, any attack vector becomes moot.

2) The IOTA Foundation and the community expressly warned not to trust unaffiliated sites. Saying they relied on them is just shady. Would we hang TBL for inventing email because people had their money stolen by nigerian scammers? No, because shifting blame on the man would be even more stupid than wiring thousands of dollars to someone you don't know. Seedgeneration is, in this current non-feature-complete implementation simply not a priority. Creating a seed is not hard and if you can't muck one up, nobody is forcing anyone to try and feed their greed trying to "enter at the ground floor, lambo lol!!!" using IOTA. I would wait for a wallet implementation that comes with a generator.

3) IOTA is very very young by far not feature complete. Hanging it out to dry because it isn't yet isn't exactly fair. Everything had to start somewhere. Though, with all that in mind, it still works rather well in my experience and it scales. It solves a lot of problems inherent with blockchain and it has a future market goal it wants to service. The rest is speculation. As always, I guess.

smrtfckr··on Why I find IOTA alarming
1) In order for the attack to succeed, the attacker would have to have access to the seed at which point the entire thing becomes moot.

2) The android wallet has seed generation. So it's not a question of "refusal", more a question of priotities. Seedgen had not been a priority of the team. We can argue if its good or bad but at the end of the day, it is what it is. Creating a seed is not hard and if you can't put in the effort, well nobody is forcing you to jump into cutting edge experimental technology in search of lambo when!!!

3) Please click "parent" on that comment in order to realize that, yes, this is not a reply to the original post of the thread but to another person unlike it was made out to be and context does matter. Who knew?

smrtfckr··on Why I find IOTA alarming
IOTA is built for the internet of things and more specifically for sensors operating in the field. Perhaps with limited acces, perhaps with long intervals between service periods. Generally, you would't care about an 8 fold efficiency increase when you're hooked up onto a powerline but remote sensing equipment does.
smrtfckr··on Why I find IOTA alarming
Still not a double spend.
smrtfckr··on Why I find IOTA alarming
You're conflating a lot of things here. Racing a fraudulent transaction to have a legitimate one confirm faster is not a double spend, like at all. Up until the moment one of the transactions confirms, no funds have changed hands. What you're also conflating is the fact that the hash collision has no influence on transacting funds in the first place. The DCI report recently released their vulnerability exploiting code which demonstrated, that in order to actually use colliding transaction hashes to create fraudulent transactions, the fraudulent party would have to have access to the seed at which point the whole thing becomes moot anyway. Adding to all this, the hashing function has long since been replaced, further compounding the moot-icity.