6 ms·
Cryptographic vulnerabilities in IOTA
- lawn 9y ago> “In 2017, leaving your crypto algorithm vulnerable to differential cryptanalysis is a rookie mistake. It says that no one of any calibre analyzed their system, and that the odds that their fix makes the system secure is low,” states Bruce Schneier, renowned security technologist, about IOTA when we shared our attack. Indeed
- otp124 9y agoMoreover, rolling their own hash function (which is what they did) is a rookie mistake.
- petertodd 9y agoNote that IOTA is a system based on ternary rather than binary, which itself is a WTF. Then on top of that, the hash function they replaced the broken one with is a wrapping of SHA3 (Keccak) with ternary. So again, they rolled their own crypto, although in a (hopefully!) more minor way. Unfortunately, doing review is a lot of hard work - I know the people involved and they had to waste time and money talking to lawyers and the like - so it's quite possible we won't find out about the flaws in their "fix" until some hacker exploits them to steal money. Even relatively small changes to hash functions and using them in non-standard ways often fails to give the security guarantees you expected. For instance, this idea from Russell O'Conner is a good example: https://lists.linuxfoundation.org/pipermail/bitcoin-dev/2017-May/014449.html https://lists.linuxfoundation.org/pipermail/bitcoin-dev/2017... His extremely professional handling of the situation is also a good example!
- th0br0 9y agoActually, SHA3 was not converted to ternary. The input is simply chunked into 243 trits that are converted to 48 bytes and are absorbed into KECCAK-384. Squeezing works the other way round, 48 bytes are squeezed and converted into 243 trits.
- petertodd 9y agoAh, that's a good point - I was aware of that, but you made me realize that using the word "convert" to describe what they did could give the wrong impression. I've changed my description to say they "wrapped" SHA3.
- deleted 9y ago[deleted]
- rubytrader 9y agoI wonder how many rookies there are in this super-hot field.
- wslh 9y agoI even think that the issues with new cryptocurrencies is underestimated in the article. The problem goes beyond the cryptographic aspect to game theoretical challenges: the cryptographic protocols could be perfect and yet the cryptocurrency be insecure or offer a low security threshold. For example, Bitcoin is perfect from the cryptographic perspective but its security threshold is around 33% [1]. Last year we also started a spreadsheet to benchmark different cryptocurrency metrics [2] but the blockchain/cryptocurrency/ICO space outpaced this initiative ;-). [1] https://arxiv.org/abs/1311.0243 https://arxiv.org/abs/1311.0243 [2] https://docs.google.com/spreadsheets/d/1DQ770nGnHfJOoRSqTLmIkhuVK5CAbs-Fgqb6UoGMfVM/edit#gid=0 https://docs.google.com/spreadsheets/d/1DQ770nGnHfJOoRSqTLmI...
- imaginenore 9y agoIt's not really a vulnerability. Miners don't have an incentive to destroy the currency with a >50% attack, they are heavily invested in it.
- wslh 9y agoThis kind of analysis are vulnerabilities in the consensus sense. You can think of a state actors not caring about the investment done but about the harm they can do.
- imaginenore 9y agoAlmost any state is capable of spending a few billion dollars and making a >50% attack (assuming they can buy enough ASICs), no matter how good your crypto is. There are much cheaper ways to bring something like Bitcoin to its knees. DDoS the nodes for a year, for instance.
- wslh 9y agoSo, are you saying that this is not part of the fundamental analysis you should do if you have money at stake? You have made such analysis to argue about the threshold numbers.
- kushti 9y agoDoing Qora code analysis few years ago, I found that not all the fields of a block are signed (made an issue, still open https://github.com/razakal/Qora/issues/14 https://github.com/razakal/Qora/issues/14), and also found some probable DoS vectors. I think many second- and third-tier cryptocurrencies are technically garbage.
- stijnh 9y agoHurts to read this. The author manages to repeat exact sentences more than two times in just a few paragraphs.
- tehlike 9y agoThere goes your hash collision.
- swordswinger12 9y agoDoes anyone know if the IOTA devs ever wrote down a justification for using a hand-rolled hash instead of, like, SHA-256? If so, can you link it in a comment? EDIT: I feel compelled to explicitly say that this was a mind-bogglingly stupid thing to do, and there is almost no way to justify it. I'm just curious what they thought they were accomplishing.
- rodarmor 9y agoThe IOTA devs are deluded. Here's there justification: "Creating a new cryptographic hash function is no trivial undertaking, even when it is being built on preexisting world class standards. “Don’t roll your own crypto” is a compulsory uttered mantra that serves as a good guiding principle for 99.9% of projects, but there are exceptions to the rule. When spearheading technology for a new paradigm this statement is no longer axiomatic. Progress must march on."
- Zarath 9y agoThe justification can be found on the Reddit: "Because we needed an efficient hash function for IoT and the future of ternary computing (memristors, spintronics, optical computing and the trend in Artificial Neural Networks) This has been known since before we even began the project. I spoke with the Keccak team about this all the way back in early 2015 before a code of IOTA was written" Source: https://gyazo.com/03cacbaf9de433c544eaffb8fd1c92ef https://gyazo.com/03cacbaf9de433c544eaffb8fd1c92ef
- sremani 9y agoThe response of sorts from IOTA team, https://blog.iota.org/curl-disclosure-beyond-the-headline-1814048d08ef https://blog.iota.org/curl-disclosure-beyond-the-headline-18...
- brohee 9y agoGood old "the vulnerability is purely theoretical". Thank God no individuals on this planet focus on making the theoretical practical, especially not when there is money at stake. That would be unsportsmanlike.
- tptacek 9y agoThe thing that I think should really worry you is that the reaction among the professional cryptographers to this (or at least the dozens I talk to on Slack and Twitter) is "well, that's cryptocurrency for you". If you have the impression that serious cryptographers are knee deep in the problem space of trying to make sure cryptocurrencies are actually secure, revise your expectations.
- pbsd 9y agoThis curl function actually came up in conversation with someone about a month ago. We figured that there was no way the core transformation was secure, and that was about the extent of our interest in it.
- tptacek 9y agoRight! I think people have a misapprehension that working cryptographers feel a kind of moral urgency to ensure that popular software is cryptographically sound. When confronted with insane stuff like IOTA, most cryptographers just drink.
- DennisP 9y agoThe ZCash team is pretty serious: https://z.cash/team.html https://z.cash/team.html
- jameskegel 9y agoTo a higher degree, one should note the Monero Research Lab is leaps and bounds ahead of ZCash.
- baby 9y agoHow? Honest question. I'm more familiar with the cryptographers behind Zcash.
- DennisP 9y agoI'm not competent to compare the work, but there don't appear to be any professional academic cryptographers on either the core or research lab teams. https://getmonero.org/resources/people.html https://getmonero.org/resources/people.html Whereas the ZCash team includes several people who were well-known cryptographers before ZCash came along.
- redka 9y agoThe title is click-bait and also somewhat wrong since the vulnerabilities discovered are curl-specific not IOTA in general and also they no longer exist since IOTA has moved to Keccak.
- rodarmor 9y agoIOTA is trash for this and other reasons. You should short it. Issues: 1. Double spends are devastating and easy, since they permanently split the tangle. 2. With no transaction limit, syncing from the beginning of time will take forever. 3. With no transaction limit, keeping up with network traffic will be impossible. (Especially on IoT devices. 4a. Nobody is going to use power and die space on IoT devices for the PoW chip. 4b. Or, alternately, if, as they claim, the PoW chip will take very little die space and very little power, the network will be destroyed outright by non-IoT PoW chips spamming the network. 5. There is currently a coordinator which confirms transactions. It is not P2P. If they remove the coordinator, I could write code that destroys the network by issuing TiB of transactions per day, making it impossible to sync/keep up. 6. Mesh networks of the type that they envisage deploying IOTA on are not widely deployed, and it's not clear that they will ever be widely deployed. 7. Tip selection does not converge.
- maxerickson 9y agoIs there a reliable exchange offering reliable short contracts?
- rodarmor 9y agoIOTA is traded on Bitfinex, which I think allows shorting, although I've never done it. One thing to keep in mind though is that the market is not particularly rational, so even though I think IOTA is doomed in the long term, in the short term it could go up, because markets. So if you do decide to short, make sure to figure out what degree of leverage is important, and what your appetite for risk is.
- montecarl 9y agoYou can only short on Bitfinex if you are not in the US.
- deleted 9y ago[deleted]
- hapahaole 9y ago
- dsacco 9y agoSigh. Exhibit A: Don't roll your own crypto...we don't just say it because it's fun. Kudos to the authors for not weaponizing the vulnerability for profit. There was no sound basis for the developers to design their own hash function, and it was a collosal mistake. It's not as if any of the other hash functions were inadequate for their security or performance needs. Frankly, I don't know if I should blame ignorance or hubris in this situation.
- laserlives 9y agoOn a seperate issue - Not a problem with IOTA but rather with seed generation using powershell. Which was a method of seed generation they recommended on their site (now removed of course). https://www.reddit.com/r/Iota/comments/6v9mj6/psa_nearly_all_powershell_generated_seeds_are/ https://www.reddit.com/r/Iota/comments/6v9mj6/psa_nearly_all...
- baby 9y agoWhy the would you invent your own cryptographic hash function. Did we do a 5 year competition bringing out the creme de la creme in cryptanalysis for nothing? Just use SHA-3 or BLAKE2.
- deleted 9y ago[deleted]
- aryehof 9y agoWhat I find disturbing is the rush to modify the subtly balanced mechanisms originally established in Bitcoin of work, reward, and punishment, in order to ensure transparency and integrity in a distributed system. This includes the subtle features and policies relating to control of the money (coin) supply, growth and hence inflation. Messing with a time proven recipe is going to result in more and more of these revelations.
- ve55 9y agoThis paints a pretty bad picture for IOTA. Ternany, custom hash functions, and a significant amount of buzzwords used to back up their poorly made choices. It's interesting their market cap is still as high as it is, although that's cryptocurrencies for you. IOTA is down around 10% in the last 24 hours, leaving it with the worst daily performance out of the top ~45 coins (https://coinmarketcap.com/ https://coinmarketcap.com/). I wonder if the authors short sold it :)
- rovek 9y agoPretty incredible that a self-proclaimed IOTA adviser thought it prudent to attack the author in public[0]. [0] - https://medium.com/@jer979/disclosure-im-an-advisor-to-iota-4956de37cfa0 https://medium.com/@jer979/disclosure-im-an-advisor-to-iota-...