<oembed><type>rich</type><version>1.0</version><author_name>npub17rld56k4365lfphyd8u8kwuejey5xcazdxptserx03wc4jc9g24stx9l2h</author_name><author_url>https://nostr.ae/npub17rld56k4365lfphyd8u8kwuejey5xcazdxptserx03wc4jc9g24stx9l2h</author_url><provider_name>njump</provider_name><provider_url>https://nostr.ae</provider_url><html>📅 Original date posted:2017-09-12&#xA;📝 Original message:On Mon, Sep 11, 2017 at 07:34:33AM -0400, Alex Morcos wrote:&#xA;&gt; I don&#39;t think I know the right answer here, but I will point out two things&#xA;&gt; that make this a little more complicated.&#xA;&gt; 1 - There are lots of altcoin developers and while I&#39;m sure the majority would&#xA;&gt; greatly appreciate the disclosure and would behave responsibly with the&#xA;&gt; information, I don&#39;t know where you draw the line on who you tell and who you&#xA;&gt; don&#39;t.&#xA;&#xA;If you can&#39;t pick even a small group that&#39;s trustworthy (top five by&#xA;market cap as a start [0]? or just major bitcoin wallets / exchanges /&#xA;alt node implementations?), then it still seems better to (eventually)&#xA;disclose publically than keep it unrevealed and let it be a potential&#xA;advantage for attackers against people who haven&#39;t upgraded for other&#xA;reasons?&#xA;&#xA;I find it hard to imagine bitcoin&#39;s still obscure enough that people&#xA;aren&#39;t tracking git commit logs to use them as inspiration for attacks&#xA;on bitcoin users and businesses; at best I would have thought it&#39;d&#xA;only be a few months of development time between a fix being proposed&#xA;as a PR or committed to master and black hats having the ability to&#xA;exploit it in users who are running older nodes. (Or for that matter,&#xA;being able to be exploited by otherwise legitimate bitcoin businesses&#xA;with an agenda to push, a strong financial motive behind that agenda,&#xA;and a legal team that says they&#39;ll get away with it)&#xA;&#xA;&gt; 2- Unlike other software, I&#39;m not sure good security for bitcoin is defined by&#xA;&gt; constant upgrading.  Obviously upgrading has an important benefit, but one of&#xA;&gt; the security considerations for Bitcoin is knowing that your definition of the&#xA;&gt; money hasn&#39;t changed.  Much harder to know that if you change software.&#xA;&#xA;Isn&#39;t that just an argument for putting more effort into backporting&#xA;fixes/workarounds? (I don&#39;t see how you do that without essentially&#xA;publically disclosing which patches have a security impact -- &#34;oh,&#xA;gosh, this patch gets a backport, I wonder if maybe it has security&#xA;implications...&#34;)&#xA;&#xA;(In so far as bitcoin is a consensus system, there can sometimes be a&#xA;positive network effect, where having other people upgrade can help your&#xA;security, even if you don&#39;t upgrade; &#34;herd immunity&#34; if you will. That&#xA;way a new release going out to other people helps keep you safe, even&#xA;while you continue to maintain the same definition of money by not&#xA;upgrading at all)&#xA;&#xA;If altcoin maintainers are inconvenienced by tracking bitcoin-core&#xA;updates, that would be an argument for them to contribute back to their&#xA;upstream to make their own job easier; either helping with backports,&#xA;or perhaps contributing to patches like PR#8994 might help.&#xA;&#xA;All of those things seem like they&#39;d help not just altcoins but bitcoin&#xA;investors/traders too, so it&#39;s not even a trade-off between classes of&#xA;bitcoin core users.  And if in the end various altcoins aren&#39;t able to&#xA;keep up with security fixes, that&#39;s probably valuable information to&#xA;provide to the market...&#xA;&#xA;Cheers,&#xA;aj&#xA;&#xA;[0] Roughly: BCash, Litecoin, Dash, BitConnect, ZCash, Dogecoin?&#xA;    I&#39;ve no idea which of those might have trustworthy devs to work with,&#xA;    but surely at least a couple do?</html></oembed>