{"type":"rich","version":"1.0","author_name":"npub1f2nvlx49er5c7sqa43src6ssyp6snd4qwvtkwm5avc2l84cs84esecrwet","author_url":"https://nostr.ae/npub1f2nvlx49er5c7sqa43src6ssyp6snd4qwvtkwm5avc2l84cs84esecrwet","provider_name":"njump","provider_url":"https://nostr.ae","html":"📅 Original date posted:2017-09-11\n📝 Original message:On Mon, Sep 11, 2017 at 5:43 PM, Daniel Stadulis via bitcoin-dev\n\u003cbitcoin-dev at lists.linuxfoundation.org\u003e wrote:\n\u003e I think it's relevant to treat different bug severity levels with different\n\u003e response plans.\n\u003e\n\u003e E.g.\n\u003e Compromising UTXO custody (In CVE-2010-5141, OP_RETURN vulnerability)\n\u003e Compromising UTXO state (In CVE-2013-3220, blockchain split due to Berkeley\n\u003e DB -\u003e LevelDB upgrade, CVE-2010-5139 Overflow bug, unscheduled inflation of\n\u003e coins)\n\u003e Compromising Node performance (Various node-specific DoS attacks)\n\u003e\n\u003e Should have different disclosure policies, IMO\n\nThis assumes the states are discernible.  They often aren't cleanly.\nYou obviously know how bad it is in the best case, but the worst could\nbe much worse.\n\nI've multiple time seen a hard to exploit issue turn out to be trivial\nwhen you find the right trick, or a minor dos issue turn our to far\nmore serious.\n\nSimple performance bugs, expertly deployed, can potentially be used to\ncarve up the network--- miner A and exchange B go in one partition,\neveryone else in another.. and doublespend.\n\nAnd so on.  So while I absolutely do agree that different things\nshould and can be handled differently, it is not always so clear cut.\nIt's prudent to treat things as more severe than you know them to be.\n\nIn fact, someone pointed out to me a major amplifier of the\nutxo-memory attack thing today that Bitcoin Core narrowly dodges which\nwould have made it very easy to exploit against some users, and which\nit seems no one previously considered.\n\nI also think it's somewhat incorrect to call this thread anything\nabout disclosure, this thread is not about disclosure. Disclosure is\nwhen you tell the vendor.  This thread is about publication and that\nhas very different implications. Publication is when you're sure\nyou've told the prospective attackers."}
