{"type":"rich","version":"1.0","author_name":"npub1vceyhqxfhemlfq82ztdv9gqgc08zq2680yzy4dfuly7h8pqrkwps0xz0wk","author_url":"https://nostr.ae/npub1vceyhqxfhemlfq82ztdv9gqgc08zq2680yzy4dfuly7h8pqrkwps0xz0wk","provider_name":"njump","provider_url":"https://nostr.ae","html":"📅 Original date posted:2016-09-09\n📝 Original message:ACK\n\nArmory used to contain code for handling these alerts but that was\nremoved after the PR removing alerts from Bitcoin Core was merged.\n\n\nOn 9/9/2016 8:42 PM, Gregory Maxwell via bitcoin-dev wrote:\n\u003e The alert system was a centralized facility to allow trusted parties\n\u003e to send messages to be displayed in wallet software (and, very early\n\u003e on, actually remotely trigger the software to stop transacting).\n\u003e\n\u003e It has been removed completely in Bitcoin Core after being disabled for a while.\n\u003e\n\u003e While the system had some potential uses, there were a number of\n\u003e problems with it.\n\u003e\n\u003e The alert system was a frequent source of misunderstanding about the\n\u003e security model and 'effective governance', for example a years ago a\n\u003e BitcoinJ developer wanted it to be used to control fee levels on the\n\u003e network and few months back one of Bloq's staff was pushing for a\n\u003e scheme where \"the developers\" would use it to remotely change the\n\u003e difficulty-- apparently with no idea how abhorrent others would find\n\u003e it.\n\u003e\n\u003e The system also had a problem of not being scalable to different\n\u003e software vendors-- it didn't really make sense that core would have\n\u003e that facility but armory had to do something different (nor would it\n\u003e really make sense to constantly have to maintain some list of keys in\n\u003e the node software).\n\u003e\n\u003e It also had the problem of being unaccountable. No one can tell which\n\u003e of the key holders created a message. This creates a risk of misuse\n\u003e with a false origin to attack someone's reputation.\n\u003e\n\u003e Finally, there is good reason to believe that the key has been\n\u003e compromised-- It was provided to MTGox by a developer and MTGox's\n\u003e systems' were compromised and later their CEO's equipment taken by the\n\u003e Japanese police.\n\u003e\n\u003e In any case, it's gone now in Core and most other current software--\n\u003e and I think it's time to fully deactivate it.\n\u003e\n\u003e I've spent some time going around the internet looking for all\n\u003e software that contains this key (which included a few altcoins) and\n\u003e asked them to remove it. I will continue to do that.\n\u003e\n\u003e One of the facilities in the alert system is that you can send a\n\u003e maximum sequence alert which cannot be overridden and displays only a\n\u003e static key compromise text message and blocks all other alerts. I plan\n\u003e to send a triggering alert in the not-distant future (exact time to be\n\u003e announced well in advance) feedback on timing would be welcome.\n\u003e\n\u003e There are likely a few production systems that automatically shut down\n\u003e when there is an alert, so this risks some small one-time disruption\n\u003e of those services-- but none worse than if an alert were sent to\n\u003e advise about a new system upgrade.\n\u003e\n\u003e At some point after that, I would then plan to disclose this private\n\u003e key in public, eliminating any further potential of reputation attacks\n\u003e and diminishing the risk of misunderstanding the key as some special\n\u003e trusted source of authority.\n\u003e\n\u003e Cheers,\n\u003e _______________________________________________\n\u003e bitcoin-dev mailing list\n\u003e bitcoin-dev at lists.linuxfoundation.org\n\u003e https://lists.linuxfoundation.org/mailman/listinfo/bitcoin-dev"}
