6 ms·
Fog.sh – decentralized content publishing on the IOTA ledger
- Egidius 9y agoOnly 4 days ago this was posted: http://codesuppository.blogspot.nl/2017/12/iota-tangled-mess.html?m=1 http://codesuppository.blogspot.nl/2017/12/iota-tangled-mess... Next to that I found this great article in the comments: https://medium.com/@neha/cryptographic-vulnerabilities-in-iota-9a6a9ddc4367 https://medium.com/@neha/cryptographic-vulnerabilities-in-io...
- nikuda 9y agoThis invention is supposedly possible through the use of something called a 'directed-acyclic-graph' Before I bought a single IOTA, I read this whitepaper and it's pretty indecipherable. I'm a pretty technical person myself, but this paper was not written in a way that anyone can easily understand. That Code Suppository "article" (blog post) is complete rubbish. The issues in 2nd article have been fixed.
- fijter 9y agoIOTA is being attacked with FUD from all sides, some people really don't want it to succeed. There's a pretty complete thread on reddit with most FUD in it and why it's not valid: https://www.reddit.com/r/Iota/comments/7j81tq/fud_copy_pastas/ https://www.reddit.com/r/Iota/comments/7j81tq/fud_copy_pasta... Here's an article by one of the IOTA founders addressing your second article: https://blog.iota.org/curl-disclosure-beyond-the-headline-1814048d08ef https://blog.iota.org/curl-disclosure-beyond-the-headline-18...
- tymbaka 9y agoEvery cryptocurrency have had their vulnerabilities at some time in the history, I don't see how this is relevant to the topic. Also he claims have been debunked by the IOTA team - https://blog.iota.org/curl-disclosure-beyond-the-headline-1814048d08ef https://blog.iota.org/curl-disclosure-beyond-the-headline-18....
- DyslexicAtheist 9y ago> I don't see how this is relevant to the topic. At least please read up and educate yourself before conditioning others into your opinion. > Also he claims have been debunked by the IOTA team only that they haven't been debunked[1]. Curl/Kerl should be reason enough for anyone to run away screaming. If somebody peddles a secure e2e encrypted messaging app based on an untested freshly invented hashing or encryption algorithm everyone would agree it's wrong. Why should the behavior displayed by IOTA team / management be treated with silk gloves? Whenever I see somebody vouching for IOTA I can only imagine 2 reasons: 1) person doesn't have a clue about basic engineering / security principles 2) person owns IOTA ans hence is personally too deep invested to be unbiased [1] https://www.linkedin.com/groups/4807429/4807429-6344511215041015812 https://www.linkedin.com/groups/4807429/4807429-634451121504...
- silversvrfer 9y agoWhenever I see somebody still commenting about Curl I can only imagine 2 reasons: 1) You lived the past several months in an island without any internet so you are not updated with the current status of the issue. 2) person invested in primitive blockchain-based coin and is personally too deep to accept innovative solutions
- RoqueNE 9y agoWonder why you only post the old negative articles. There are maybe 5 articles that claim they found something negative, but 20 that are positive or directly debunking the negative articles using credible professional sources. The nonsense about the 'vulnerability' neha found got destroyed in multiple answers. either directly from the devs or from independent sources. Just yesterday one of the core devs answered (again) to the claim by narula: https://medium.com/@comefrombeyond/cfbs-comments-on-https-www-media-mit-edu-posts-iota-response-5834c7f8172d https://medium.com/@comefrombeyond/cfbs-comments-on-https-ww... Your post shows the classical signs of a FUD-Attack. Excellent explained in this article: https://www.psychologytoday.com/blog/mind-in-the-machine/201712/how-fear-is-being-used-manipulate-cryptocurrency-markets https://www.psychologytoday.com/blog/mind-in-the-machine/201.... Here is IOTA as Victim of ongoing targeted FUD-Campains identified.
- aqsheehy 9y agoBecause he's not invested in iota like you clearly are.
- silversvrfer 9y agoYou don't have to be invested in something to be unbiased.
- RoqueNE 9y agoHow does the fact that he is not invested give him the right to spread false informations and throw dirt? When i see bullshit, i call it out. simple as that. My opinion is as good as his. But my sources are much better and reliably researched and obviously not biased.
- detaro 9y agoA developer defending his project with a blogpost that mostly seems preoccupied with attacking the authors instead of their argument is "obviously not biased"? That response makes them look even worse.
- 9y ago
- silversvrfer 9y agoSo this John Ratcliff is actually crying because he can't reuse his address after sending from it. Please do know that Iota uses Winternitz one-time signature. Iota team discussed already the pros and cons of this choice. And not reusable address is a known and conscious decision from the devs.
- xwvvvvwx 9y agoNot really deep into this, and haven't even read the whitepaper, but looking from the outside there are a lot of red flags around this project: - Use of ternary logic [1] - Writing their own hash function [1] - Claiming that the flaws in the hash function were 'copy protection' [2] - The Github issues page for their wallet client [3] I've heard that the DAG approach has merit, but from what I've seen I would not trust this team to execute on it. [EDIT]: Almost forgot the black-box closed source 'central coordinator' [4] [1]: https://medium.com/@neha/cryptographic-vulnerabilities-in-iota-9a6a9ddc4367 https://medium.com/@neha/cryptographic-vulnerabilities-in-io... [2]: https://gist.githubusercontent.com/Come-from-Beyond/a84ab8615aac13a4543c786f9e35b84a/raw/bb00cdf3625deba453d614f55c27f769b261df56/CFB's%2520letters%2520to%2520Neha%2520Narula's%2520team%2520during%2520their%2520analysis%2520of%2520Curl-P%2520hash%2520function https://gist.githubusercontent.com/Come-from-Beyond/a84ab861... [3]: https://github.com/iotaledger/wallet/issues https://github.com/iotaledger/wallet/issues [4]: https://www.reddit.com/r/Iota/comments/7c3qu8/coordinator_explained/ https://www.reddit.com/r/Iota/comments/7c3qu8/coordinator_ex...
- silversvrfer 9y agoHi, -Can you explain why the use of ternary logic is red flag? I can explain why it is not but you have to justify your statement first. You calling the use of ternary logic a red flag must be based off of something I assume. -They used a custom Hash functio called "Curl". But they now replaced it with KECCAK-384. Curl is now being reviewed by a third party. -For this, I will let CFB (one of the devs) to explain. https://medium.com/@comefrombeyond/cfbs-comments-on-https-www-media-mit-edu-posts-iota-response-5834c7f8172d https://medium.com/@comefrombeyond/cfbs-comments-on-https-ww... -wallet is a nuisance for some users I agree. But majority of users are fine with the wallet. Of course you can only hear those who had problems.
- xwvvvvwx 9y agoTernary logic is a pretty niche thing. As I understand it the claimed benefit is improved efficiency / elegance for some mathematical operations when run on a ternary computer. However since all modern hardware is binary, the use of ternary logic only serves to introduce an unnecessary software based translation layer, simultaneously increasing complexity and reducing performance. I would consider this to be an example of very poor engineering judgement. Good software is simple software. I would be extremely concerned if a colleague suggested such needless overcomplication.
- zaidf 9y agoWhat's actually stored on the ledger? Like if I make a blog post with title "Hello world" and body "1234", would those two strings be on the ledger?
- degif 9y agoHey, one of the authors here. Short answer - yes. Together with some meta data, the published content is signed by the author, encrypted (read more here on how exactly https://blog.iota.org/introducing-masked-authenticated-messaging-e55c1822d50e https://blog.iota.org/introducing-masked-authenticated-messa...) and stored on the Tangle. Fog CMS helps with the content publishing and is one of the ways on how to read and display the content from the Tangle.
- degif 9y agoHey, one of the developers here! Happy to see this on Hacker news, thought the CMS is still in heavy development. Happy to answer questions and I hope we can stay on the problem/technology/product topic and oversee all the crazy speculation stuff ;)
- xwvvvvwx 9y agoNice work! This seems really slick :) How has your experience of building with IOTA been? Is there a good SDK / documentation somewhere? I've just started digging into Ethereum and so far I've been a bit disappointed by the standard of the tooling... :/
- degif 9y agoRight now IOTA works as a content storage and distribution "database" regarding to what we are building, so it's more simple than Ethereum smart contracts and their own language. The API SDK's are all there and are working great for us!
- xwvvvvwx 9y agoDoes the SDK call out to some server running a node somewhere, or does it actually implement a client side IOTA node in JS?
- degif 9y agoTo check the data authenticity it's connecting to a node server for the data synchronisation, the data encryption happens on the client side. Client side nodes are on IOTAs roadmap as it's a technical challenge to synchronise with the network by just storing a small chunk of it.
- xwvvvvwx 9y agoWho runs the server? What incentive do they have to expend resources to commit data to the ledger? How can you trust that they have committed what you asked them to?
- mntmn 9y agoJust remember that all the message/transaction metadata is purged when the IOTA team makes a “snapshot”. One of my first evaluations of IOTA was to store IPFS URLs in transactions. Then came a snapshot and all the data was gone. This probably wouldn’t happen in a system with transaction fees.
- forvelin 9y agoAmount of 'newbie investors' in IOTA and their over-zealous defence in any medium is scary. We've had Perl people, Python people, Ruby people and their arguments but none of those invested their money in languages' success. This blockchain programming zeal mixed with investors trying to hype their currency is annoying and mildly scary.
- DyslexicAtheist 9y agoindeed very distracting! Becomes impossible to argue when everyone is so pumped by their possible financial ROI that they're blind to any criticism. And then there is the fanboys / evangelists who sign up to forums like this just for spreading their belief. Like mindless bots. The whole technology is fascinating but it's a pain for researching facts when half the community is biased the other half are morons.
- caruana 9y agoI know this will get down votes (but I'm generally a sarcastic guy so please take this in that spirit): if half are biased and half are morons what camp do you fall in? :)
- DyslexicAtheist 9y agoYou don't have to be part of the crypto-zoo. You can just stand on the side observing and shaking your head. Disclaimer: I personally don't gamble/speculate and therefore don't have any crypto currencies in my possession. (this argument is usually used by IOTA fanboys to discredit critics of their currency/ICO)
- caruana 9y agoStanding on the side lines, indirectly referring to participants as animals (crypto-zoo), shaking your head from your percieved superior position, generalizing participation as gambling / speculating demonstrates you are squarely in the biased 50% camp. My Disclaimer: I have positions in several crypto projects (not IOTA specifically b/c I don't like some of the decisions they've made). I make no predictions as to which (if any) cryto projects will succeed but ultimately I think that the long term outlook is positive for a few. edit - typo
- hasa 9y agoDoes the particular content object live as single chunk of data in the decentralized network or as multiplicated copies as in case of virtual currencies ?
- leichtgewicht 9y agoI don't see an advantage to https://datproject.org https://datproject.org ?! Do I miss something?
- DennisP 9y agoThis seems like it might be interesting if there were some technical detail about how it actually works.