Bitcoin Forum
May 07, 2024, 08:07:29 PM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: Lighting Network Security Issues  (Read 167 times)
ChiBitCTy (OP)
Legendary
*
Offline Offline

Activity: 2254
Merit: 3008



View Profile
September 02, 2019, 06:48:40 AM
 #1

Interesting article put out by Forbes that discusses some recently discovered LN issues. They haven’t released specifics yet due to not wanting others to exploit these issues, however it mentions the importance of having updated nodes or else you’re risking the loss of your coins. It also mentions to make sure you keep the eclair app updated, which I can attest first hand that if it’s not it won’t properly function.

Curious as to what the issue is. Here’s the link - https://www.forbes.com/sites/billybambrough/2019/09/01/bitcoin-warning-as-serious-security-vulnerabilities-uncovered/amp/

███████████████████████████
███████▄████████████▄██████
████████▄████████▄████████
███▀█████▀▄███▄▀█████▀███
█████▀█▀▄██▀▀▀██▄▀█▀█████
███████▄███████████▄███████
███████████████████████████
███████▀███████████▀███████
████▄██▄▀██▄▄▄██▀▄██▄████
████▄████▄▀███▀▄████▄████
██▄███▀▀█▀██████▀█▀███▄███
██▀█▀████████████████▀█▀███
███████████████████████████
.
.Duelbits.
..........UNLEASH..........
THE ULTIMATE
GAMING EXPERIENCE
DUELBITS
FANTASY
SPORTS
████▄▄█████▄▄
░▄████
███████████▄
▐███
███████████████▄
███
████████████████
███
████████████████▌
███
██████████████████
████████████████▀▀▀
███████████████▌
███████████████▌
████████████████
████████████████
████████████████
████▀▀███████▀▀
.
▬▬
VS
▬▬
████▄▄▄█████▄▄▄
░▄████████████████▄
▐██████████████████▄
████████████████████
████████████████████▌
█████████████████████
███████████████████
███████████████▌
███████████████▌
████████████████
████████████████
████████████████
████▀▀███████▀▀
/// PLAY FOR  FREE  ///
WIN FOR REAL
..PLAY NOW..
1715112449
Hero Member
*
Offline Offline

Posts: 1715112449

View Profile Personal Message (Offline)

Ignore
1715112449
Reply with quote  #2

1715112449
Report to moderator
1715112449
Hero Member
*
Offline Offline

Posts: 1715112449

View Profile Personal Message (Offline)

Ignore
1715112449
Reply with quote  #2

1715112449
Report to moderator
Even in the event that an attacker gains more than 50% of the network's computational power, only transactions sent by the attacker could be reversed or double-spent. The network would not be destroyed.
Advertised sites are not endorsed by the Bitcoin Forum. They may be unsafe, untrustworthy, or illegal in your jurisdiction.
1715112449
Hero Member
*
Offline Offline

Posts: 1715112449

View Profile Personal Message (Offline)

Ignore
1715112449
Reply with quote  #2

1715112449
Report to moderator
1715112449
Hero Member
*
Offline Offline

Posts: 1715112449

View Profile Personal Message (Offline)

Ignore
1715112449
Reply with quote  #2

1715112449
Report to moderator
Pmalek
Legendary
*
Offline Offline

Activity: 2758
Merit: 7135



View Profile
September 02, 2019, 07:30:45 AM
 #2

We will have to wait until 27 September to find out what vulnerabilities they discovered. The article doesn't mention any recommendations or warnings to users to stop using eclair for the time being so we can assume that as long as you keep everything up to date there shouldn't be major reasons for concern.

.
.BLACKJACK ♠ FUN.
█████████
██████████████
████████████
█████████████████
████████████████▄▄
░█████████████▀░▀▀
██████████████████
░██████████████
████████████████
░██████████████
████████████
███████████████░██
██████████
CRYPTO CASINO &
SPORTS BETTING
▄▄███████▄▄
▄███████████████▄
███████████████████
█████████████████████
███████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
███████████████████████
█████████████████████
███████████████████
▀███████████████▀
█████████
.
Carlton Banks
Legendary
*
Offline Offline

Activity: 3430
Merit: 3074



View Profile
September 02, 2019, 07:34:09 AM
 #3

it sounds like a protocol level flaw, as all clients were affected (at least both c-lightning and lnd anyway)

but we don't know yet, the c-lightning team and the lnd team released fixed clients, then waited, then made an announcement that a flaw exists, but not the details of the flaw. this is the most responsible way to handle it, as many people (including myself) had already upgraded their Lightning daemon anyway.


There's no evidence that any funds have been stolen using the still-not-public flaw, so any tangible fallout from this event should be minimal to none.

Vires in numeris
Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!