{"type":"rich","version":"1.0","author_name":"npub1f2nvlx49er5c7sqa43src6ssyp6snd4qwvtkwm5avc2l84cs84esecrwet","author_url":"https://nostr.ae/npub1f2nvlx49er5c7sqa43src6ssyp6snd4qwvtkwm5avc2l84cs84esecrwet","provider_name":"njump","provider_url":"https://nostr.ae","html":"📅 Original date posted:2016-09-09\n📝 Original message:The alert system was a centralized facility to allow trusted parties\nto send messages to be displayed in wallet software (and, very early\non, actually remotely trigger the software to stop transacting).\n\nIt has been removed completely in Bitcoin Core after being disabled for a while.\n\nWhile the system had some potential uses, there were a number of\nproblems with it.\n\nThe alert system was a frequent source of misunderstanding about the\nsecurity model and 'effective governance', for example a years ago a\nBitcoinJ developer wanted it to be used to control fee levels on the\nnetwork and few months back one of Bloq's staff was pushing for a\nscheme where \"the developers\" would use it to remotely change the\ndifficulty-- apparently with no idea how abhorrent others would find\nit.\n\nThe system also had a problem of not being scalable to different\nsoftware vendors-- it didn't really make sense that core would have\nthat facility but armory had to do something different (nor would it\nreally make sense to constantly have to maintain some list of keys in\nthe node software).\n\nIt also had the problem of being unaccountable. No one can tell which\nof the key holders created a message. This creates a risk of misuse\nwith a false origin to attack someone's reputation.\n\nFinally, there is good reason to believe that the key has been\ncompromised-- It was provided to MTGox by a developer and MTGox's\nsystems' were compromised and later their CEO's equipment taken by the\nJapanese police.\n\nIn any case, it's gone now in Core and most other current software--\nand I think it's time to fully deactivate it.\n\nI've spent some time going around the internet looking for all\nsoftware that contains this key (which included a few altcoins) and\nasked them to remove it. I will continue to do that.\n\nOne of the facilities in the alert system is that you can send a\nmaximum sequence alert which cannot be overridden and displays only a\nstatic key compromise text message and blocks all other alerts. I plan\nto send a triggering alert in the not-distant future (exact time to be\nannounced well in advance) feedback on timing would be welcome.\n\nThere are likely a few production systems that automatically shut down\nwhen there is an alert, so this risks some small one-time disruption\nof those services-- but none worse than if an alert were sent to\nadvise about a new system upgrade.\n\nAt some point after that, I would then plan to disclose this private\nkey in public, eliminating any further potential of reputation attacks\nand diminishing the risk of misunderstanding the key as some special\ntrusted source of authority.\n\nCheers,"}
