Bitcoin Forum
May 25, 2024, 11:26:02 PM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: « 1 [2]  All
  Print  
Author Topic: BIP39 lookup table for paranoids  (Read 510 times)
pseudo_geek (OP)
Newbie
*
Offline Offline

Activity: 21
Merit: 10


View Profile
December 07, 2020, 12:15:47 PM
 #21

That's also what happened to the SSL 3.0 RFC after the POODLE attack was discovered, they published a new one that deprecated its use.

SSL/TLS session is transient thing. Therefore, it's less painful to migrate to upgraded/patched new protocol - although it's not completely painless, because there's many situations where installed old software can't be (easily) upgraded.

Meanwhile this is where alternatives to BIP39 have got us to:

https://imgs.xkcd.com/comics/standards.png

Agreed.
pseudo_geek (OP)
Newbie
*
Offline Offline

Activity: 21
Merit: 10


View Profile
December 07, 2020, 12:19:55 PM
 #22

Once a BIP is published it becomes very hard to walk it back short of a major security vulnerability found in the design in which case they would theoretically release another BIP that deprecates the previous one, in fact that's sort of what happened to BIP39 (minus "major") if you read the comments on the github mediawiki page in the bips/ repo they wrote that they discourage its use. That's also what happened to the SSL 3.0 RFC after the POODLE attack was discovered, they published a new one that deprecated its use.

Honestly I don't think BIP39 has fatal problems, although it indeedly has many imperfections. It doesn't seem to be the same case of something like POODLE attack - as long as you use SSL3.0, you are always vulnerable to such attacks; however just keep using BIP39 doesn't seem to introduce similar risks.
Pages: « 1 [2]  All
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!