Re: [bitcoin-dev] Responsible disclosure of bugs

2017-09-10 Thread Anthony Towns via bitcoin-dev
On Sun, Sep 10, 2017 at 07:02:36PM -0400, Matt Corallo via bitcoin-dev wrote: > I believe there continues to be concern over a number of altcoins which > are running old, unpatched forks of Bitcoin Core, making it rather > difficult to disclose issues without putting people at risk (see, eg, > some

Re: [bitcoin-dev] Responsible disclosure of bugs

2017-09-10 Thread CryptAxe via bitcoin-dev
I don't think we should put any Bitcoin users at additional risk to help altcoins. If they fork the code they are making maintenance their own responsibly. It's hard to disclose a bitcoin vulnerability considering the network is decentralised and core can't force everyone to update. Maybe a timeou

Re: [bitcoin-dev] Responsible disclosure of bugs

2017-09-10 Thread Matt Corallo via bitcoin-dev
I believe there continues to be concern over a number of altcoins which are running old, unpatched forks of Bitcoin Core, making it rather difficult to disclose issues without putting people at risk (see, eg, some of the dos issues which are preventing release of the alert key). I'd encourage the l

Re: [bitcoin-dev] Fwd: Sidechain headers on mainchain (unification of drivechains and spv proofs)

2017-09-10 Thread ZmnSCPxj via bitcoin-dev
Sent with [ProtonMail](https://protonmail.com) Secure Email. > Original Message > Subject: Re: Fwd: [bitcoin-dev] Sidechain headers on mainchain (unification > of drivechains and spv proofs) > Local Time: September 9, 2017 3:33 PM > UTC Time: September 9, 2017 3:33 PM > From: tr

Re: [bitcoin-dev] Fwd: Sidechain headers on mainchain (unification of drivechains and spv proofs)

2017-09-10 Thread ZmnSCPxj via bitcoin-dev
Good morning Paul, Thank you for your consideration. >> 1. Unifies merge mining (h* commitment) and WT^ validity voting. >> Merge-mined headers increase the vote on a WT^, by increasing the depth >> of the WT^. > >1. I think it is a mistake for SHOM ("Sidechain Headers on Mainchain") >to "unify m

[bitcoin-dev] Responsible disclosure of bugs

2017-09-10 Thread Simon Liu via bitcoin-dev
Hi, Given today's presentation by Chris Jeffrey at the Breaking Bitcoin conference, and the subsequent discussion around responsible disclosure and industry practice, perhaps now would be a good time to discuss "Bitcoin and CVEs" which has gone unanswered for 6 months. https://lists.linuxfoundati