Re: [bitcoin-dev] Responsible disclosure of bugs

2017-09-10 Thread Anthony Towns via bitcoin-dev
On Sun, Sep 10, 2017 at 07:02:36PM -0400, Matt Corallo via bitcoin-dev wrote: > I believe there continues to be concern over a number of altcoins which > are running old, unpatched forks of Bitcoin Core, making it rather > difficult to disclose issues without putting people at risk (see, eg, >

Re: [bitcoin-dev] Responsible disclosure of bugs

2017-09-10 Thread CryptAxe via bitcoin-dev
I don't think we should put any Bitcoin users at additional risk to help altcoins. If they fork the code they are making maintenance their own responsibly. It's hard to disclose a bitcoin vulnerability considering the network is decentralised and core can't force everyone to update. Maybe a

Re: [bitcoin-dev] Responsible disclosure of bugs

2017-09-10 Thread Matt Corallo via bitcoin-dev
I believe there continues to be concern over a number of altcoins which are running old, unpatched forks of Bitcoin Core, making it rather difficult to disclose issues without putting people at risk (see, eg, some of the dos issues which are preventing release of the alert key). I'd encourage the

Re: [bitcoin-dev] Fwd: Sidechain headers on mainchain (unification of drivechains and spv proofs)

2017-09-10 Thread ZmnSCPxj via bitcoin-dev
Sent with [ProtonMail](https://protonmail.com) Secure Email. > Original Message > Subject: Re: Fwd: [bitcoin-dev] Sidechain headers on mainchain (unification > of drivechains and spv proofs) > Local Time: September 9, 2017 3:33 PM > UTC Time: September 9, 2017 3:33 PM > From:

[bitcoin-dev] Responsible disclosure of bugs

2017-09-10 Thread Simon Liu via bitcoin-dev
Hi, Given today's presentation by Chris Jeffrey at the Breaking Bitcoin conference, and the subsequent discussion around responsible disclosure and industry practice, perhaps now would be a good time to discuss "Bitcoin and CVEs" which has gone unanswered for 6 months.