5 ms·
Everything in that blog post is very much what the rest of the industry is agreeing with. Sources backing this up is even cited in the damn blog post man.
by Aledgerly 9y ago
Everything in that blog post is very much what the rest of the industry is agreeing with. Sources backing this up is even cited in the damn blog post man.
- guiomie 9y agoHis point is valid, it does sound like oil snake marketing.
- ktta 9y agoWhat industry? You mean the one that is less than 5yrs old? IOTA itself, with all its 'smarts' made a stupid mistake designing their own cryptographic hash function! This might seem like I'm hanging on a single point, but I guarantee, any sane security person on this site will tell you to stay far away from this coin if they see this. https://medium.com/@neha/cryptographic-vulnerabilities-in-iota-9a6a9ddc4367 https://medium.com/@neha/cryptographic-vulnerabilities-in-io...
- flaminghedge 9y agoPeople design hash functions. Repeating that ‘creating a hash function is stupid’ doesn’t make it true. There is a need for an efficient, lightweight cryptographic standard for low resource devices. Curl-P attempts to be this solution utilizing ternary logic. They aren’t making it just because they can. There is a real need for it. Recently, with the Foundation being established (therefore giving them access to sufficient funds), they hired CYBERCRYPT to vet and improve upon their prototype.
- ktta 9y ago>Repeating that ‘creating a hash function is stupid’ doesn’t make it true. There's a process for everything. Cryptographic functions are supposed to undergo atleast half a decade of peer testing before they can be used with any reasonable sense of security. Creating them isn't stupid. Creating them and using them in your application without proper security testing is. If 'ternary' logic based hash didn't exist, then sure, create one. But don't tout it as being anywhere close to ready when it is important to the overall security of the system. The project justifies their decision to do so about 'spearheading technology for a new paradigm', which further solidifies the fact they value short-term risky benefits over long term research which is what science is supposed to be.
- flaminghedge 9y agoThere is no arbitrary time length requirement for security. There are standard tests (like avalanche) all of which Curl-P passed. They passed all the standard security requirements before deploying the prototype, and had a backup plan of deploying keccak should a hint of any possible exploit arise. Curl-P is based on a well-studied sponge construction, so it’s not an especially risky move to deploy it in their system after it passed all initial security requirements. Curl-P also has the advantage of being extremely simple. This makes it easier to vet as the analysis can be done more thoroughly, as it’s not obscured through complex internal mechanisms. It does require new tools to study (as it’s ternary) so there is bound to be some delay to extremely thorough production readiness. However, saying it is not close to being ready is false (unless we must put an arbitrary year requirement on it as you seem to be keen on).
- ktta 9y ago>There is no arbitrary time length requirement for security. No there isn't, but it is about letting more researchers take a crack at it. With well-known competitions, you can expect cryptographers to take a look at it. The thing is, I've heard of lots of new hashes in the past couple years but only heard about curl when the vulnerability was found. I'm not saying I was on the lookout for new hashes but didn't find any, but how do you except people to check it out when no one really knows about it? Even decades of time is worthless when you have no one looking at it. >There are standard tests (like avalanche) all of which Curl-P passed. That's basic homework, not the real test, which is analysis done by people. Give me some tets, a couple months and I can come up with a hash function which passes those too. >Curl-P is based on a well-studied sponge construction, so it’s not an especially risky move Sure, sponge construction, while new has been studied due to Keccak. But you should've used keccak, instead of creating a new one(As they're doing now) > Curl-P also has the advantage of being extremely simple. This makes it easier to vet as the analysis can be done more thoroughly, as it’s not obscured through complex internal mechanisms. You know what, I'm not a cryptographer, so I'll quote what a real cryptographer - Bruce Schneier has to say about that. “In 2017, leaving your crypto algorithm vulnerable to differential cryptanalysis is a rookie mistake. It says that no one of any calibre analyzed their system, and that the odds that their fix makes the system secure is low,” What do you have to say to this? >However, saying it is not close to being ready is false (unless we must put an arbitrary year requirement on it as you seem to be keen on). Arbitrary year requirement seems frivolous, because you don't see the cryptographers who work hard quietly till they have an attack ready. It is to give time for them. Take a look at previous competitions, where attacks surface many years after first publication.
- QML 9y agoPerhaps the true mission of IOTA is to provide the largest bug bounty for a cryptographic hash function ever?