<oembed><type>rich</type><version>1.0</version><author_name>npub17rld56k4365lfphyd8u8kwuejey5xcazdxptserx03wc4jc9g24stx9l2h</author_name><author_url>https://nostr.ae/npub17rld56k4365lfphyd8u8kwuejey5xcazdxptserx03wc4jc9g24stx9l2h</author_url><provider_name>njump</provider_name><provider_url>https://nostr.ae</provider_url><html>📅 Original date posted:2017-09-12&#xA;📝 Original message:On Mon, Sep 11, 2017 at 10:43:52AM -0700, Daniel Stadulis wrote:&#xA;&gt; I think it&#39;s relevant to treat different bug severity levels with different&#xA;&gt; response plans. &#xA;&#xA;That makes sense.&#xA;&#xA;For comparison, Monero defines a response process that has three levels&#xA;and varies the response for each:&#xA;&#xA;]     a. HIGH: impacts network as a whole, has potential to break entire&#xA;]        network, results in the loss of monero, or is on a scale of great&#xA;]        catastrophe&#xA;]     b. MEDIUM: impacts individual nodes, wallets, or must be carefully&#xA;]        exploited&#xA;]     c. LOW: is not easily exploitable&#xA;&#xA; -- https://github.com/monero-project/monero/blob/master/VULNERABILITY_RESPONSE_PROCESS.md&#xA;&#xA;Among other things, HIGH gets treated as an emergency, MEDIUM get fixed&#xA;in a point release; LOW get deferred to the next regular release eg.&#xA;&#xA;Additionally, independently of the severity, Monero&#39;s doc says they&#39;ll&#xA;either get their act together with a fix and report within 90 days,&#xA;or otherwise the researcher that found the vulnerability has the right&#xA;to publically disclose the issue themselves...&#xA;&#xA;I wouldn&#39;t say that&#39;s a perfect fit for bitcoin core (at a minimum, given&#xA;the size of the ecosystem and how much care needs to go into releases,&#xA;I think 90 days is probably too short), but it seems better than current&#xA;practice...&#xA;&#xA;For comparison, if you&#39;re an altcoin developer or just bitcoin core user,&#xA;and are trying to work out whether the software you&#39;re using is secure;&#xA;if you do a quick google and end up at:&#xA;&#xA;  https://en.bitcoin.it/wiki/Common_Vulnerabilities_and_Exposures&#xA;&#xA;you might conclude that as long as you&#39;re running version 0.11 or later,&#xA;you&#39;re fine. That doesn&#39;t seem like an accurate conclusion for people&#xA;to draw; but if you&#39;re not tracking every commit/PR, how do you do any&#xA;better than that?&#xA;&#xA;Maybe transitioning from keeping things private indefinitely to having&#xA;a public disclosure policy is tricky. Maybe it might work to build up to it,&#xA;something like:&#xA;&#xA;  * We&#39;ll start releasing info about security vulnerabilities fixed in&#xA;    0.12.0 and earlier releases as of 2018-01-01&#xA;  * Then we&#39;ll continue with 0.13.0 and earlier as of 2018-03-01&#xA;  * Likewise for 0.14.0 as of 2018-05-01&#xA;  * Thereafter we&#39;ll adopt a regular policy at http://...&#xA;&#xA;That or something like it at least gives people relying on older,&#xA;potentially vulnerable versions a realistic chance to privately prepare&#xA;and deploy any upgrades or fixes they&#39;ve missed out on until now.&#xA;&#xA;Cheers,&#xA;aj</html></oembed>