<oembed><type>rich</type><version>1.0</version><author_name>npub1vceyhqxfhemlfq82ztdv9gqgc08zq2680yzy4dfuly7h8pqrkwps0xz0wk</author_name><author_url>https://nostr.ae/npub1vceyhqxfhemlfq82ztdv9gqgc08zq2680yzy4dfuly7h8pqrkwps0xz0wk</author_url><provider_name>njump</provider_name><provider_url>https://nostr.ae</provider_url><html>📅 Original date posted:2016-09-09&#xA;📝 Original message:ACK&#xA;&#xA;Armory used to contain code for handling these alerts but that was&#xA;removed after the PR removing alerts from Bitcoin Core was merged.&#xA;&#xA;&#xA;On 9/9/2016 8:42 PM, Gregory Maxwell via bitcoin-dev wrote:&#xA;&gt; The alert system was a centralized facility to allow trusted parties&#xA;&gt; to send messages to be displayed in wallet software (and, very early&#xA;&gt; on, actually remotely trigger the software to stop transacting).&#xA;&gt;&#xA;&gt; It has been removed completely in Bitcoin Core after being disabled for a while.&#xA;&gt;&#xA;&gt; While the system had some potential uses, there were a number of&#xA;&gt; problems with it.&#xA;&gt;&#xA;&gt; The alert system was a frequent source of misunderstanding about the&#xA;&gt; security model and &#39;effective governance&#39;, for example a years ago a&#xA;&gt; BitcoinJ developer wanted it to be used to control fee levels on the&#xA;&gt; network and few months back one of Bloq&#39;s staff was pushing for a&#xA;&gt; scheme where &#34;the developers&#34; would use it to remotely change the&#xA;&gt; difficulty-- apparently with no idea how abhorrent others would find&#xA;&gt; it.&#xA;&gt;&#xA;&gt; The system also had a problem of not being scalable to different&#xA;&gt; software vendors-- it didn&#39;t really make sense that core would have&#xA;&gt; that facility but armory had to do something different (nor would it&#xA;&gt; really make sense to constantly have to maintain some list of keys in&#xA;&gt; the node software).&#xA;&gt;&#xA;&gt; It also had the problem of being unaccountable. No one can tell which&#xA;&gt; of the key holders created a message. This creates a risk of misuse&#xA;&gt; with a false origin to attack someone&#39;s reputation.&#xA;&gt;&#xA;&gt; Finally, there is good reason to believe that the key has been&#xA;&gt; compromised-- It was provided to MTGox by a developer and MTGox&#39;s&#xA;&gt; systems&#39; were compromised and later their CEO&#39;s equipment taken by the&#xA;&gt; Japanese police.&#xA;&gt;&#xA;&gt; In any case, it&#39;s gone now in Core and most other current software--&#xA;&gt; and I think it&#39;s time to fully deactivate it.&#xA;&gt;&#xA;&gt; I&#39;ve spent some time going around the internet looking for all&#xA;&gt; software that contains this key (which included a few altcoins) and&#xA;&gt; asked them to remove it. I will continue to do that.&#xA;&gt;&#xA;&gt; One of the facilities in the alert system is that you can send a&#xA;&gt; maximum sequence alert which cannot be overridden and displays only a&#xA;&gt; static key compromise text message and blocks all other alerts. I plan&#xA;&gt; to send a triggering alert in the not-distant future (exact time to be&#xA;&gt; announced well in advance) feedback on timing would be welcome.&#xA;&gt;&#xA;&gt; There are likely a few production systems that automatically shut down&#xA;&gt; when there is an alert, so this risks some small one-time disruption&#xA;&gt; of those services-- but none worse than if an alert were sent to&#xA;&gt; advise about a new system upgrade.&#xA;&gt;&#xA;&gt; At some point after that, I would then plan to disclose this private&#xA;&gt; key in public, eliminating any further potential of reputation attacks&#xA;&gt; and diminishing the risk of misunderstanding the key as some special&#xA;&gt; trusted source of authority.&#xA;&gt;&#xA;&gt; Cheers,&#xA;&gt; _______________________________________________&#xA;&gt; bitcoin-dev mailing list&#xA;&gt; bitcoin-dev at lists.linuxfoundation.org&#xA;&gt; https://lists.linuxfoundation.org/mailman/listinfo/bitcoin-dev</html></oembed>