<oembed><type>rich</type><version>1.0</version><author_name>npub12p7jzesdg8kxdg8rujr20znnd868fgugczkwh4cyxwa6gnxj5sxsnjs309</author_name><author_url>https://nostr.ae/npub12p7jzesdg8kxdg8rujr20znnd868fgugczkwh4cyxwa6gnxj5sxsnjs309</author_url><provider_name>njump</provider_name><provider_url>https://nostr.ae</provider_url><html>📅 Original date posted:2017-09-10&#xA;📝 Original message:I don&#39;t think we should put any Bitcoin users at additional risk to help&#xA;altcoins. If they fork the code they are making maintenance their own&#xA;responsibly.&#xA;&#xA;It&#39;s hard to disclose a bitcoin vulnerability considering the network is&#xA;decentralised and core can&#39;t force everyone to update. Maybe a timeout&#xA;period for vulnerabilities could be decided. People might be expected to&#xA;patched before then at which point the vulnerability can be published. Is&#xA;that not already sort of how it works?&#xA;&#xA;On Sep 10, 2017 4:10 PM, &#34;Matt Corallo via bitcoin-dev&#34; &lt;&#xA;bitcoin-dev at lists.linuxfoundation.org&gt; wrote:&#xA;&#xA;&gt; I believe there continues to be concern over a number of altcoins which&#xA;&gt; are running old, unpatched forks of Bitcoin Core, making it rather&#xA;&gt; difficult to disclose issues without putting people at risk (see, eg,&#xA;&gt; some of the dos issues which are preventing release of the alert key).&#xA;&gt; I&#39;d encourage the list to have a discussion about what reasonable&#xA;&gt; approaches could be taken there.&#xA;&gt;&#xA;&gt; On 09/10/17 18:03, Simon Liu via bitcoin-dev wrote:&#xA;&gt; &gt; Hi,&#xA;&gt; &gt;&#xA;&gt; &gt; Given today&#39;s presentation by Chris Jeffrey at the Breaking Bitcoin&#xA;&gt; &gt; conference, and the subsequent discussion around responsible disclosure&#xA;&gt; &gt; and industry practice, perhaps now would be a good time to discuss&#xA;&gt; &gt; &#34;Bitcoin and CVEs&#34; which has gone unanswered for 6 months.&#xA;&gt; &gt;&#xA;&gt; &gt; https://lists.linuxfoundation.org/pipermail/bitcoin-dev/&#xA;&gt; 2017-March/013751.html&#xA;&gt; &gt;&#xA;&gt; &gt; To quote:&#xA;&gt; &gt;&#xA;&gt; &gt; &#34;Are there are any vulnerabilities in Bitcoin which have been fixed but&#xA;&gt; &gt; not yet publicly disclosed?  Is the following list of Bitcoin CVEs&#xA;&gt; &gt; up-to-date?&#xA;&gt; &gt;&#xA;&gt; &gt; https://en.bitcoin.it/wiki/Common_Vulnerabilities_and_Exposures&#xA;&gt; &gt;&#xA;&gt; &gt; There have been no new CVEs posted for almost three years, except for&#xA;&gt; &gt; CVE-2015-3641, but there appears to be no information publicly available&#xA;&gt; &gt; for that issue:&#xA;&gt; &gt;&#xA;&gt; &gt; https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-3641&#xA;&gt; &gt;&#xA;&gt; &gt; It would be of great benefit to end users if the community of clients&#xA;&gt; &gt; and altcoins derived from Bitcoin Core could be patched for any known&#xA;&gt; &gt; vulnerabilities.&#xA;&gt; &gt;&#xA;&gt; &gt; Does anyone keep track of security related bugs and patches, where the&#xA;&gt; &gt; defect severity is similar to those found on the CVE list above?  If&#xA;&gt; &gt; yes, can that list be shared with other developers?&#34;&#xA;&gt; &gt;&#xA;&gt; &gt; Best Regards,&#xA;&gt; &gt; Simon&#xA;&gt; &gt; _______________________________________________&#xA;&gt; &gt; bitcoin-dev mailing list&#xA;&gt; &gt; bitcoin-dev at lists.linuxfoundation.org&#xA;&gt; &gt; https://lists.linuxfoundation.org/mailman/listinfo/bitcoin-dev&#xA;&gt; &gt;&#xA;&gt; _______________________________________________&#xA;&gt; bitcoin-dev mailing list&#xA;&gt; bitcoin-dev at lists.linuxfoundation.org&#xA;&gt; https://lists.linuxfoundation.org/mailman/listinfo/bitcoin-dev&#xA;&gt;&#xA;-------------- next part --------------&#xA;An HTML attachment was scrubbed...&#xA;URL: &lt;http://lists.linuxfoundation.org/pipermail/bitcoin-dev/attachments/20170910/1b3bfb59/attachment.html&gt;</html></oembed>