10 ms·
Why I find IOTA alarming
- simias 9y agoI feel like I'm missing one side of the story. I don't know much about IOTA but from what I learned reading articles linked on HN today IOTA: - Uses custom "ternary" crypto which has been shown to have vulnerabilities in the past. - Has software that doesn't include the basic function of generating wallet addresses, instead having some users rely on shady 3rd party websites and getting their coins stolen. - Does away with much of what made other cryptocurrencies like Bitcoin work in the first place in order to remove transaction limitations. - Except that the changes required to make this work, at least in theory, are for the most part not actually implemented yet and there appears to be a lot of doubts that it can work at all. See for instance this comment on the article: https://medium.com/@comefrombeyond/thank-you-269640e794e7 https://medium.com/@comefrombeyond/thank-you-269640e794e7 ("in the future", "temporarily", "will be using",...). Also note that many replies in this comment actually deflect the original criticism without actually addressing it. I don't even understand what that person means by "You describe the internet", and how that has anything to do with the argument of TFA. So basically you have a highly experimental technology (even by cryptocurrency standards) which is very much unproven (even by cryptocurrency standards) and yet apparently it has a market cap of $6 billions: https://coinmarketcap.com/currencies/iota/ https://coinmarketcap.com/currencies/iota/ So what's the other side of the story? Can a IOTA enthusiast explain what's missing from this picture?
- empath75 9y agoBlockchain + IOT = enough buzzwords to profit off of the greater fool theory.
- jaimehrubiks 9y agoWho said blockchain?
- Cthulhu_ 9y agoThey do. (IOTA - Next Generation Blockchain)[https://iota.org/ https://iota.org/]
- api 9y agoAlso note the extremely flashy web site.
- indoordinosaur 9y agoThe fact that it is using balanced Ternary makes it seem like the science project of young/inexperienced developers. If you're building a cryptocurrency put away your hubris and use what is tried-and-true.
- kruhft 9y agoFrom their Learning IOTA FAQ: What makes IOTA quantum-secure? IOTA uses hash-based signatures (https://www.imperialviolet.org/2013/07/18/hashsig.html https://www.imperialviolet.org/2013/07/18/hashsig.html) instead of elliptic curve cryptography (ECC). Not only is hash-based signatures a lot faster than ECC, but it also greatly simplifies the overall protocol (signing and verification). What actually makes IOTA quantum-secure is the fact that we use Winternitz signatures. IOTA's ternary hash function is called Curl.)[1] Curl is designed by Genetic Algorithm. I wonder how they could test this? Did they 'do the math'? [1] https://learn.iota.org/faq/what-makes-iota-quantum-secure https://learn.iota.org/faq/what-makes-iota-quantum-secure
- indoordinosaur 9y agoIn the original article linked it talks about how people found a flaw in the cryptographic hash function. When it was pointed out to the founder he basically said "Yeah we knew it was not secure. We put it in there so if anyone copied our code we could undermine them." That smells fishy to me. Whether his statement is true or not he cannot be trusted. And the fact that they are using unproven in-house cryptography again supports my view of IOTA as a science project rather that something serious and dependable.
- kruhft 9y agoI asked them about it. They agreed after I said it was like 'inserting fake roads into a map by cartographers'. Seemed a bit fishy to me too. Math project is more likely.
- api 9y agoHash sigs... ok Winternitz... ok Ternary hash function ... designed by genetic algorith ... WUT? Why would you design your own hash function?
- vvangemert 9y ago1. There have been no vulnerabilities in the past. Please read: https://blog.iota.org/official-iota-foundation-response-to-the-digital-currency-initiative-at-the-mit-media-lab-part-1-72434583a2 https://blog.iota.org/official-iota-foundation-response-to-t... 2. If people are unable to generate a simple seed (password) on their own. How can they even begin to understand cryptocurrency or even new tech based on IoT? Still, yes it should be in the wallet and it will be added, but only for investors, I guess?! 3. Please read the following from their AMA: https://www.reddit.com/r/Iota/comments/7goul4/iota_founders_ama_summary_of_important_questions/ https://www.reddit.com/r/Iota/comments/7goul4/iota_founders_... and https://www.reddit.com/r/Iota/comments/7tltz2/live_interview_with_david_s%C3%B8nsteb%C3%B8_founder_of/ https://www.reddit.com/r/Iota/comments/7tltz2/live_interview... Is their market cap justified? Is the entire crypto market cap justified? The whole idea is to invest in tech that can change the future. Who knows which party will be the winner. It's a dare to believe in something magical, like IOTA. Or put your luck into something more real like Bitcoin, for example. Alas, it's good to have doubts, but this blogpost is alarming and not IOTA. PS: A small portion of my crypto investments are in IOTA, but never press your luck on a single coin.
- lgierth 9y ago> 1. There have no vulnerabilities in the past. I don't know man, the MIT Digital Currency Initiative found a pretty bad one last August: https://medium.com/@neha/cryptographic-vulnerabilities-in-iota-9a6a9ddc4367 https://medium.com/@neha/cryptographic-vulnerabilities-in-io... > the IOTA developers had written their own hash function, Curl, and it produced collisions (when different inputs hash to the same output). Once we developed our attack, we could find collisions using commodity hardware within just a few minutes, and forge signatures on IOTA payments. We informed the IOTA developers, they patched their system, and we wrote a vulnerability report
- lgierth 9y agoDCI's report: https://github.com/mit-dci/tangled-curl/blob/master/vuln-iota.md https://github.com/mit-dci/tangled-curl/blob/master/vuln-iot...
- 9y ago
- berberous 9y agoBitConnect, a literal Ponzi scheme that was repeatedly flagged to newbies as a Ponzi scheme they should avoid, had a $2.5 billion market cap last month before collapsing. While IOTA boosters probably have a story they believe that justifies the hype in their mind, just because it’s worth $6 billion in this market doesn’t mean they necessarily have a good one. For what it’s worth, of all the crypto people I follow that I consider smart or savvy, none of them are IOTA bulls. Also, the IOTA founder comes off as extremely immature on twitter each time someone trashes it. Even if all the criticism is FUD, his reaction alone is enough to keep me away.
- minxomat 9y agoExperienced the immaturity first hand, see https://news.ycombinator.com/item?id=15860968 https://news.ycombinator.com/item?id=15860968
- asymmetric 9y agoOT: who are the crypto people you follow? And on which channels? Twitter seems sadly popular among this crowd. Sadly because it lends itself to flamewars.
- berberous 9y agoHere are two resources that I think are helpful: 1. Token Economy is a weekly crypto newsletter run by two crypto VCs (https://tokeneconomy.co/ https://tokeneconomy.co/). I think it is extremely good at separating the signal from the noise. Highly recommend. 2. Twitter is unfortunately indeed the easiest place to follow what's going on. Naval Ravikant, the founder of AngelList, recently published a list of the people he follows in the space (https://twitter.com/naval/lists/crypto/members https://twitter.com/naval/lists/crypto/members). It has a large overlap with my own list, but neither he nor I endorse everyone's views that are on it. But it probably includes most of the active developers, VCs and thought leaders in the space.
- mynegation 9y agoOh, you meant cryptocurrencies, not the cryptography people. "Crypto" is an established abbreviation for "cryptography". Probably, to avoid confusion we should spell out both terms.
- api 9y agoCustom crypto primitives (ciphers, hashes, etc.) is a big red flag to me unless the designers are cryptographers. I know a fair bit about crypto. I would implement (and have implemented) higher order constructions like encrypted and authenticated protocols according to design patterns and principles put forward by competent cryptographers. I would never ever even attempt to design a cipher or a cryptographically strong hash unless I were just playing around, and would never label my work as anything other than such. Even trying to innovate on constructions (like how to combine a MAC with a cipher) would make me very nervous and I'd seek the advice of a pro. Multiply that nervousness by ten if the system is a cryptocurrency, which has a big "hack me" sign on it with a massive cash bounty. Actual deep cryptography such as cipher design is an area where truly extreme and very esoteric expertise is required to even get started, and where the consequences of a failure are pretty dire. Even people who can design ciphers are conservatives when they implement real secure systems, only using those ciphers that have been through years of academic cryptanalysis. This area is very different from other areas of computer science and math.
- asymmetric 9y ago> Actual deep cryptography such as cipher design is an area where truly extreme and very esoteric expertise is required to even get started I hear this every time cryptography is brought up. I think I get that it's hard, but people make it sound like it's the hardest thing ever. Where does this extreme complexity stem from? And what's the field of knowledge required? (Mathematics I imagine)
- berberous 9y agoI think the problem is that it's tricky math, and there are so many possible subtle failure modes that make a scheme insecure (e.g., timing attacks). So in order to have a chance of making a new secure scheme, you should be an expert in crpyotgraphy (i.e., be very familiar with past schemes, why they worked, and common ways schemes fail that are non-obvious to someone without such a background). Furthermore, given the number of subtle failure modes, a new scheme (even one designed by an expert) is likely to be insecure until shown to be secure by time and peer review (i.e., after it has been extensively attacked). Experts know this; amateurs assume that because they can't see a flaw, their new scheme is secure enough to deploy.
- granaldo 9y ago$6b market cap as of now and to think that it used to be $14b https://www.coingecko.com/en/price_charts/iota/usd https://www.coingecko.com/en/price_charts/iota/usd was madness enough
- etunity 9y agoTheir argument for using ternary is that it is 8 times more efficient than binary and it is very important for iot devices which need to be have low energy consumption and a long life. Whereas the conversation from ternary to binary would add only a 10 % additional usage. They are trying to push the ternary to see if adoption can take off. All it needs is a few thousand logic gates on any traditional chip.if it doesn’t get adopted,they said they can always go back to binary.
- imglorp 9y ago> 8 times more efficient than binary They're claiming this, for what operation? And similar question for the 10% usage claim. I suspect storage will be the same when you get done packing into machine words and storing those, yes? Unless they're not using all the bits in a word... Any independent references for ternary efficiencies for any operation?
- smrtfckr 9y agoIOTA is built for the internet of things and more specifically for sensors operating in the field. Perhaps with limited acces, perhaps with long intervals between service periods. Generally, you would't care about an 8 fold efficiency increase when you're hooked up onto a powerline but remote sensing equipment does.
- imglorp 9y agoGreat, someone else quoting 8x efficiency. Maybe you know about the claim? We understand the motivation, which keeps getting mentioned, but what I think we all want to know is: 8x efficiency _of_what_compared_to_what_?
- PinguTS 9y agoSuch devices are using ARM Cortex M0, M1, or M3 processors. Maybe even lower power Atmel stuff like in the Arduino. Such devices are connected via either expansive uplinks or slow uplinks like with LPWAN. For all these applications IOTA is not feasible. It is not feasible because the ternary logic needs to be emulated on a processor that itself has not even enough beef to do cryptographic functions by itself. If they have cryptographic support like the e.g. the SE series from STM with a Cortex M0 as used in the Ledger Nano S, then this is optimized for standard cryptographic algorithms and not for some newly invented stuff. Also if we talk about IOT sensor networking with LPWAN (LoRa, SigFox, ...) than bandwith is a real issue. That means collecting transactions from others and doing PoW on that before sending of your own transaction is completely unrealistic. The remote sensor just wants to transmit its data. But that would mean the LPWAN Gateway needs to be a full node doing the PoW. But LPWAN works, that everybody can listen to transaction request and so we are back to the collisions problem.
- PinguTS 9y agoThe fun part is, that if you want to discuss such details (and I have much more) with an IOTA enthusiast, I get thinks like "I don't understand the technical details, but the founders say so you must be wrong. You are just discredit me." So you, how want to discuss the details when people are just convinced without having knowledge themselves?
- kruhft 9y agoBelief is real.
- PinguTS 9y agoEven the double spending problem is not really resolved. Just with the current theft, there are recipes posted[1] on how to recover the stolen IOTA by basically enforcing the double spending and trying to give your spending a higher priority than the fraudulent transactions had. That means fraudulent transaction could try this themselves and just need to exploit that race condition. That means a fraud needs to somehow collect the data on pending transactions and just need to issue their own ones with the known collision problem on the hash. [1] https://www.inowrx.de/iota-stolen-iota-stop-pending-unconfirmed-transactions-try-to-rescue-your-iota-wallet/ https://www.inowrx.de/iota-stolen-iota-stop-pending-unconfir...
- etunity 9y agoFor the double spend to occur, you would need access to the seed ( private key) which the victims had and are trying to outrun the attacker in the case you were describing.
- smrtfckr 9y agoStill not a double spend.
- elmar 9y ago>For the double spend to occur, you would need access to the seed ( private key) which the victims had and are trying to outrun the attacker in the case you were describing. So it works a bit like replace-by-fee on bitcoin? There is no mining on IOTA so what is the possible time frame? do you have more detailed technical information how this works? Thanks
- etunity 9y agoNew transactions are selected randomly to be verified. So in case the attackers transaction is still not confirmed there is a chance to outspend him by having the private keys. I find this useful in understanding the confirmation/consensus mechanism. https://forum.iota.org/t/iota-consensus-masterclass/1193 https://forum.iota.org/t/iota-consensus-masterclass/1193
- deleted 9y ago[deleted]
- smrtfckr 9y ago1) No, the whole implementation of the ledger is written in ternary. Its current hasing function is called Kerl. The vulnerability that DCI claimed existed is impossible to be used in the wild because an attacker would have to have seed level access to the wallet at which point, any attack vector becomes moot. 2) The IOTA Foundation and the community expressly warned not to trust unaffiliated sites. Saying they relied on them is just shady. Would we hang TBL for inventing email because people had their money stolen by nigerian scammers? No, because shifting blame on the man would be even more stupid than wiring thousands of dollars to someone you don't know. Seedgeneration is, in this current non-feature-complete implementation simply not a priority. Creating a seed is not hard and if you can't muck one up, nobody is forcing anyone to try and feed their greed trying to "enter at the ground floor, lambo lol!!!" using IOTA. I would wait for a wallet implementation that comes with a generator. 3) IOTA is very very young by far not feature complete. Hanging it out to dry because it isn't yet isn't exactly fair. Everything had to start somewhere. Though, with all that in mind, it still works rather well in my experience and it scales. It solves a lot of problems inherent with blockchain and it has a future market goal it wants to service. The rest is speculation. As always, I guess.
- mikeash 9y agoWhy would ternary be at all a good basis for this sort of software? I could imagine some use cases at the hardware level, but in software it’s just nonsense.
- alfonsodev 9y agoThis[1] is a recent (yesterday) interview with David Sønstebø founder of IOTA. He addresses the points you are mentioning. [1] https://www.youtube.com/watch?v=GwhJQ67zxbg https://www.youtube.com/watch?v=GwhJQ67zxbg
- bitoneill 9y agoYou can read more concerns about IOTA and ternary in this thread: https://news.ycombinator.com/item?id=15980675 https://news.ycombinator.com/item?id=15980675 IOTA rebutted MIT here: https://blog.iota.org/official-iota-foundation-response-to-the-digital-currency-initiative-at-the-mit-media-lab-part-4-11fdccc9eb6d https://blog.iota.org/official-iota-foundation-response-to-t...
- rspeer 9y agoEven the rebuttal is immature and badly thought out, much like their cryptography. They start by implying that the MIT Media Lab isn't really MIT (what the fuck) as an ad-hominem way to dodge their criticism. Later they whine "But Zcash rolled their own crypto, why can't we?!" which shows they really don't even understand the context of what they're doing.
- raitucarp 9y agoI just copy paste from CfB's response, in case you missed it: Thank you. This article was useful for me, it showed what details of IOTA haven’t been highlighted yet. Below I list incorrect things from the article, if you find time it would be great if you paid more attention to them and shared your thoughts: “IOTA has no limit on transactions and therefore, it has no limit on bandwidth requirements or disk space.” — In the future the majority of the nodes will be swarm nodes forming clusters and using Swarm Intelligence. A swarm can process more transactions than a single full node. “This means, if you run a full IOTA node, anyone on the IOTA network can write data to your hard drive with just a small, extremely low cost proof-of-work.” — IOTA was created for the Internet-of-Things with network-bound PoW in mind, the current state of things is temporary. “Over time, the IOTA transaction set size can grow unbounded, leaving only storage farms with the resources required to host the data.” — This is incorrect even for Bitcoin because of pruning techniques. “My past experience working at companies that develop hardware products tells me this does not make sense in any other way but a marketing bullet.” — While this thing is likely correct I decided to list it here. IOTA team has experience working at companies developing hardware products too. Even more, I bet your smartphone contains a chip developed by one of our advisors. “IOTA claims their Ternary-based Proof-of-Work function will work with IOT because it uses minimal power, but I contend that any power usage more significant than signing a transaction is too much because there is another alternative approach.” — As I already said, IOTA will be using network-bound PoW, which will be consuming less energy than required for a transaction signing. “Contacting a central server run by the company that built the IOT device, announcing the need to submit a transaction at which point the centralized server will submit the transaction on the device’s behalf.” — You described the Internet, not the IoT. Please, refer to “Connectivity” section of https://iot.ieee.org/newsletter/march-2017/three-major-challenges-facing-iot https://iot.ieee.org/newsletter/march-2017/three-major-chall..., it explains why you are very wrong. “In the case of IOTA the client software design intends to kick nodes off the network that do not participate enough, so being even just a passive listener is not an option.” — And again you talk about the Internet, not about the IoT. Googling for reasons of not using IP(v4/v6) should show you the mistake. I don’t mention insignificant mistakes in your reasoning, all those seem to be caused by the lack of information about IOTA. This is an issue that the IOTA team is working on.
- 9y ago
- machinecontrol 9y agoIt's fascinating how some cryptocurrencies are starting to generally move towards centralization and away from the core principles of Bitcoin.
- omnivagus 9y agoyou're judging what you obviously have no idea?
- StavrosK 9y agoOh man, this article reminded me I should sell what little IOTA I have, so I tried to. Here's what happened: I launched my wallet and saw a zero balance and zero transactions. I looked around and heard from some friends that I need to convert my funds or something, because there was a "snapshot" yesterday. I clicked the "re-attach" button and waited for a few minutes. It failed, so I did it again and again and again. After half an hour and five times or so, it succeeded and I could see my balance. I tried to send funds, the wallet said "sending" for around ten minutes, and then it finally said "success". I waited for the funds to confirm (there were three transactions, two of which were zero for some reasons), but 70 minutes later it still hadn't. A friend told me I should "re-attach" the transaction and "promote" it. Apparently, "promoting" sends five transactions that reference yours, to confirm it. I imagine the transactions are zero-fund transactions that just spam the network to self-confirm your own one. Who confirms the confirmers? This is absolutely insane and I can't believe this thing ever got traction. It feels like hacks upon hacks upon hacks. It doesn't even work right! Did any of the people who bought these coins try to ever use them for anything?
- cocktailpeanuts 9y agoNo offense but your comment is unintentionally humorous because you're asking all these sane questions blaming the mindless people who bought into IOTA, but you happen to be one of them as you describe yourself. > This is absolutely insane and I can't believe this thing ever got traction. It got traction because people--including yourself--bought into it without thinking much. > It feels like hacks upon hacks upon hacks. It doesn't even work right! Did any of the people who bought these coins try to ever use them for anything? Yeah, like yourself. You never actually tried to use the coins for anything until this point when you are now finally trying to "cash out".
- StavrosK 9y ago> You never actually tried to use the coins for anything until this point when you are now finally trying to "cash out". An alternate (and correct) interpretation is that I bought IOTA as I thought I may end up using it in my IoT projects. I didn't (probably because nobody working for IOTA actually cares about IoT), and now I want to sell them for a more useful currency. Not everyone wants coins for speculation, but you're forgiven for thinking otherwise.
- thisisit 9y agoI have been on HN for 3 years now but I have never seen anything like this thread. There are sheer amount of sockpuppet accounts being created to defend IOTA.
- Lewton 9y agoYou know how people can get irrationally invested in defending gaming consoles because they’ve bought one for $500? Imagine what it feels like when you have tens of thousands of dollars invested in something where the flamewars might actually have a real effect on whether you ten-double your investment or not I think it’s gonna get much uglier than this down the road
- dang 9y agoIt happens sometimes when a popular project gets criticized on HN and people make accounts to defend it. What we do in such cases is close the thread to new accounts, and we've done that here.