<oembed><type>rich</type><version>1.0</version><author_name>npub1f2nvlx49er5c7sqa43src6ssyp6snd4qwvtkwm5avc2l84cs84esecrwet</author_name><author_url>https://nostr.ae/npub1f2nvlx49er5c7sqa43src6ssyp6snd4qwvtkwm5avc2l84cs84esecrwet</author_url><provider_name>njump</provider_name><provider_url>https://nostr.ae</provider_url><html>📅 Original date posted:2017-09-11&#xA;📝 Original message:On Mon, Sep 11, 2017 at 5:43 PM, Daniel Stadulis via bitcoin-dev&#xA;&lt;bitcoin-dev at lists.linuxfoundation.org&gt; wrote:&#xA;&gt; I think it&#39;s relevant to treat different bug severity levels with different&#xA;&gt; response plans.&#xA;&gt;&#xA;&gt; E.g.&#xA;&gt; Compromising UTXO custody (In CVE-2010-5141, OP_RETURN vulnerability)&#xA;&gt; Compromising UTXO state (In CVE-2013-3220, blockchain split due to Berkeley&#xA;&gt; DB -&gt; LevelDB upgrade, CVE-2010-5139 Overflow bug, unscheduled inflation of&#xA;&gt; coins)&#xA;&gt; Compromising Node performance (Various node-specific DoS attacks)&#xA;&gt;&#xA;&gt; Should have different disclosure policies, IMO&#xA;&#xA;This assumes the states are discernible.  They often aren&#39;t cleanly.&#xA;You obviously know how bad it is in the best case, but the worst could&#xA;be much worse.&#xA;&#xA;I&#39;ve multiple time seen a hard to exploit issue turn out to be trivial&#xA;when you find the right trick, or a minor dos issue turn our to far&#xA;more serious.&#xA;&#xA;Simple performance bugs, expertly deployed, can potentially be used to&#xA;carve up the network--- miner A and exchange B go in one partition,&#xA;everyone else in another.. and doublespend.&#xA;&#xA;And so on.  So while I absolutely do agree that different things&#xA;should and can be handled differently, it is not always so clear cut.&#xA;It&#39;s prudent to treat things as more severe than you know them to be.&#xA;&#xA;In fact, someone pointed out to me a major amplifier of the&#xA;utxo-memory attack thing today that Bitcoin Core narrowly dodges which&#xA;would have made it very easy to exploit against some users, and which&#xA;it seems no one previously considered.&#xA;&#xA;I also think it&#39;s somewhat incorrect to call this thread anything&#xA;about disclosure, this thread is not about disclosure. Disclosure is&#xA;when you tell the vendor.  This thread is about publication and that&#xA;has very different implications. Publication is when you&#39;re sure&#xA;you&#39;ve told the prospective attackers.</html></oembed>