{"type":"rich","version":"1.0","author_name":"npub12p7jzesdg8kxdg8rujr20znnd868fgugczkwh4cyxwa6gnxj5sxsnjs309","author_url":"https://nostr.ae/npub12p7jzesdg8kxdg8rujr20znnd868fgugczkwh4cyxwa6gnxj5sxsnjs309","provider_name":"njump","provider_url":"https://nostr.ae","html":"📅 Original date posted:2017-09-10\n📝 Original message:I don't think we should put any Bitcoin users at additional risk to help\naltcoins. If they fork the code they are making maintenance their own\nresponsibly.\n\nIt's hard to disclose a bitcoin vulnerability considering the network is\ndecentralised and core can't force everyone to update. Maybe a timeout\nperiod for vulnerabilities could be decided. People might be expected to\npatched before then at which point the vulnerability can be published. Is\nthat not already sort of how it works?\n\nOn Sep 10, 2017 4:10 PM, \"Matt Corallo via bitcoin-dev\" \u003c\nbitcoin-dev at lists.linuxfoundation.org\u003e wrote:\n\n\u003e I believe there continues to be concern over a number of altcoins which\n\u003e are running old, unpatched forks of Bitcoin Core, making it rather\n\u003e difficult to disclose issues without putting people at risk (see, eg,\n\u003e some of the dos issues which are preventing release of the alert key).\n\u003e I'd encourage the list to have a discussion about what reasonable\n\u003e approaches could be taken there.\n\u003e\n\u003e On 09/10/17 18:03, Simon Liu via bitcoin-dev wrote:\n\u003e \u003e Hi,\n\u003e \u003e\n\u003e \u003e Given today's presentation by Chris Jeffrey at the Breaking Bitcoin\n\u003e \u003e conference, and the subsequent discussion around responsible disclosure\n\u003e \u003e and industry practice, perhaps now would be a good time to discuss\n\u003e \u003e \"Bitcoin and CVEs\" which has gone unanswered for 6 months.\n\u003e \u003e\n\u003e \u003e https://lists.linuxfoundation.org/pipermail/bitcoin-dev/\n\u003e 2017-March/013751.html\n\u003e \u003e\n\u003e \u003e To quote:\n\u003e \u003e\n\u003e \u003e \"Are there are any vulnerabilities in Bitcoin which have been fixed but\n\u003e \u003e not yet publicly disclosed?  Is the following list of Bitcoin CVEs\n\u003e \u003e up-to-date?\n\u003e \u003e\n\u003e \u003e https://en.bitcoin.it/wiki/Common_Vulnerabilities_and_Exposures\n\u003e \u003e\n\u003e \u003e There have been no new CVEs posted for almost three years, except for\n\u003e \u003e CVE-2015-3641, but there appears to be no information publicly available\n\u003e \u003e for that issue:\n\u003e \u003e\n\u003e \u003e https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-3641\n\u003e \u003e\n\u003e \u003e It would be of great benefit to end users if the community of clients\n\u003e \u003e and altcoins derived from Bitcoin Core could be patched for any known\n\u003e \u003e vulnerabilities.\n\u003e \u003e\n\u003e \u003e Does anyone keep track of security related bugs and patches, where the\n\u003e \u003e defect severity is similar to those found on the CVE list above?  If\n\u003e \u003e yes, can that list be shared with other developers?\"\n\u003e \u003e\n\u003e \u003e Best Regards,\n\u003e \u003e Simon\n\u003e \u003e _______________________________________________\n\u003e \u003e bitcoin-dev mailing list\n\u003e \u003e bitcoin-dev at lists.linuxfoundation.org\n\u003e \u003e https://lists.linuxfoundation.org/mailman/listinfo/bitcoin-dev\n\u003e \u003e\n\u003e _______________________________________________\n\u003e bitcoin-dev mailing list\n\u003e bitcoin-dev at lists.linuxfoundation.org\n\u003e https://lists.linuxfoundation.org/mailman/listinfo/bitcoin-dev\n\u003e\n-------------- next part --------------\nAn HTML attachment was scrubbed...\nURL: \u003chttp://lists.linuxfoundation.org/pipermail/bitcoin-dev/attachments/20170910/1b3bfb59/attachment.html\u003e"}
