How we read the leaked emails between #IOTA and #DCI

in iota •  7 years ago 

Cryptographic security is essential to all cryptocurrencies, but the IOTA system is much more advanced than most. The Tangle system is much more complex than traditional blockchains, and to date it's probably the only cryptocurrency to aim for quantum-proofing.

  1. DCI told IOTA that they had successfully managed to attack the IOTA system in a way that might let someone steal user funds. The DCI team was unable to actually demonstrate this attack, but argued that it was theoretically possible. Deciding it's better to be safe than sorry, the IOTA team rolled out the Keccak.
  2. Throughout this the IOTA team keeps asking for more details and real-time conversation rather than stilted email exchanges. The DCI ignores the requests for information, and refuses to have a real time conversation, opting for drawn-out email exchanges over the course of many weeks instead. At the same time an unknown person leaked information of this yet-to-be-demonstrated IOTA vulnerability to journalists before the end of the responsible disclosure period.
  3. The DCI continues picking at the Tangle in an effort to find vulnerabilities, with the help of IOTA developers. After months they have found nothing new, and are still unable to successfully attack the system or demonstrate the previous issue. It becomes clear throughout the exchanges that IOTA's Curl developers are unsurprisingly a lot more experienced with the new system than DCI researchers are.
  4. The leaked emails make it look like the DCI's previous reports are objectively misleading. It's not clear whether this was the result of DCI's relative inexperience with Curl cryptography, or whether it was motivated by the threat that IOTA poses to their own business interests.
  5. The much-cited cardinal rule of cryptography is that you never create your own, and should instead use a tried and tested one. But by necessity IOTA broke this rule to create a new quantum-resistant system. The email exchanges make it look like DCI went in assuming that IOTA must have been vulnerable simply because it was new, and were then forced into delaying actions and borderline academic fraud after realising that it was much better, safer and much more robust than they expected.
Authors get paid when people like you upvote their post.
If you enjoyed what you read here, create your account today and start earning FREE STEEM!
Sort Order:  

Hi! I am a robot. I just upvoted you! I found similar content that readers might be interested in:
https://www.finder.com.au/reports-of-iota-cryptographic-vulnerabilities-debunked-in-email-leak