3 ms·
What is there even to discuss? The disclosures and email tell me everything I wanted to know.
by TD-Linux 9y ago
What is there even to discuss? The disclosures and email tell me everything I wanted to know.
- mbgaxyz 9y agoWhere is the code which exploits the supposed vulnerability in IOTA? After all, there are code samples available today which demonstrate the SPECTRE and MELTDOWN attacks.
- espadrine 9y agoThat is akin to this: “Hey, your house door is unlocked.” “What are you talking about? I left it unlocked on purpose, but it is safe, I wired the metal handle to the power plug, nobody bad can get in.” “What about the good ones?” “I installed a Coordinator™ that calls me when you ring, and I can open the door remotely.” “Wait, didn’t you make this house with the promise that everyone with the key could use it?” “… well, I don’t see you finding a vulnerability!”
- DyslexicAtheist 9y agodiscussing vulnerabilities is misleading since it's in this case not something you can put into a PoC. It's not code that's vulnerable¹. The whole argument is that the math is wrong but more correctly should be that the behavior of Curl has never been defined. You can't proof something doesn't behave the way it should when it was never defined what that behavior is in the first place. ¹ though there are several actual code vulns that have been dismissed by the IOTA team as "FUD" and even threatening researchers with litigation https://prizz.github.io/iota-transaction-spammer-webapp/ https://prizz.github.io/iota-transaction-spammer-webapp/
- zaarn 9y agoThere are explanations on how it works here [https://archive.is/6imWR https://archive.is/6imWR] [http://www.tangleblog.com/wp-content/uploads/2018/02/letters.pdf http://www.tangleblog.com/wp-content/uploads/2018/02/letters...] You don't need code to prove that a vulnerability exists, it is sufficient, especially for crypto primitives like hash functions or cipher rounds, that there is a mathematical vulnerability that can be potentially exploited.