Bitcoin Forum
May 13, 2024, 03:39:09 AM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: [2020-09-12]Researcher kept a Bitcoin bug secret for 2 years to prevent attacks  (Read 199 times)
Karartma1 (OP)
Legendary
*
Offline Offline

Activity: 2310
Merit: 1422



View Profile
September 14, 2020, 10:02:17 AM
 #1

In 2018, a security researcher discovered a major vulnerability in Bitcoin Core, the software that powers the Bitcoin blockchain, but after reporting the issue and having it patched, the researcher opted to keep details private in order to avoid hackers exploiting the issue.
Technical details were published earlier this week after the same vulnerability was independently discovered in another cryptocurrency, based on an older version of the Bitcoin code that hadn't received the patch.
https://www.zdnet.com/article/researcher-kept-a-major-bitcoin-bug-secret-for-two-years-to-prevent-attacks/
1715571549
Hero Member
*
Offline Offline

Posts: 1715571549

View Profile Personal Message (Offline)

Ignore
1715571549
Reply with quote  #2

1715571549
Report to moderator
1715571549
Hero Member
*
Offline Offline

Posts: 1715571549

View Profile Personal Message (Offline)

Ignore
1715571549
Reply with quote  #2

1715571549
Report to moderator
"Governments are good at cutting off the heads of a centrally controlled networks like Napster, but pure P2P networks like Gnutella and Tor seem to be holding their own." -- Satoshi
Advertised sites are not endorsed by the Bitcoin Forum. They may be unsafe, untrustworthy, or illegal in your jurisdiction.
1715571549
Hero Member
*
Offline Offline

Posts: 1715571549

View Profile Personal Message (Offline)

Ignore
1715571549
Reply with quote  #2

1715571549
Report to moderator
1715571549
Hero Member
*
Offline Offline

Posts: 1715571549

View Profile Personal Message (Offline)

Ignore
1715571549
Reply with quote  #2

1715571549
Report to moderator
1715571549
Hero Member
*
Offline Offline

Posts: 1715571549

View Profile Personal Message (Offline)

Ignore
1715571549
Reply with quote  #2

1715571549
Report to moderator
hv_
Legendary
*
Offline Offline

Activity: 2506
Merit: 1055

Clean Code and Scale


View Profile WWW
September 14, 2020, 10:57:33 AM
 #2

Some critical business (e..g railway,...)  with very high standards have to wait up to 10y to be 'allowed' to use a new tech for the public to be settled - exactly for that reason.

All such forks (hard/soft) and alterations happening to bcore, bcash, eth, .. are just a nightmare / nogo for any enterprise business btw

Carpe diem  -  understand the White Paper and mine honest.
Fix real world issues: Check out b-vote.com
The simple way is the genius way - Satoshi's Rules: humana veris _
thirdkiller
Full Member
***
Offline Offline

Activity: 301
Merit: 100



View Profile
September 14, 2020, 03:16:27 PM
 #3

In any case, over time, hackers would have found this vulnerability, I'm sure of it.
Harlot
Hero Member
*****
Offline Offline

Activity: 1806
Merit: 671


View Profile
September 14, 2020, 07:09:57 PM
 #4

I think they have done right on doing so. Vulnerabilities where it hasn't been resolve yet shouldn't be disclose to anyone not unless the vulnerability is related to users doing a certain action like how older versions of Electrum are bring controlled by hackers. By staying silent they are giving themselves time to fix the issue not worsen the scenario where hackers might have the idea of doing the vulnerability said by them.
InvoKing
Legendary
*
Offline Offline

Activity: 2142
Merit: 1065


✋(▀Ĺ̯ ▀-͠ )


View Profile WWW
September 14, 2020, 10:00:52 PM
 #5

In any case, over time, hackers would have found this vulnerability, I'm sure of it.
Fixing the bug quickly will prevents any harm for users keeping their software up to date. Using an old version is not recommended and always risky  Undecided

PSPD:law and order enforcement!
Press Section Police Department!
Kakmakr
Legendary
*
Offline Offline

Activity: 3444
Merit: 1957

Leading Crypto Sports Betting & Casino Platform


View Profile
September 16, 2020, 07:38:15 AM
 #6

Is there some kind of reward for people to receive if they find vulnerabilities like this? Who would be funding such a reward, if it does exist?  I know exchanges and wallet providers will offer a reward, if someone finds an exploit in their code, but we know where they get there funds from.  Wink

In any way, most people are invested in Crypto currencies that has the knowledge to find these so-called "bugs" ...so it is in their best interest to keep it a secret, because it will have a major influence on the value of their own hoard.. if the exploit is made public before it is patched.  Wink

..Stake.com..   ▄████████████████████████████████████▄
   ██ ▄▄▄▄▄▄▄▄▄▄            ▄▄▄▄▄▄▄▄▄▄ ██  ▄████▄
   ██ ▀▀▀▀▀▀▀▀▀▀ ██████████ ▀▀▀▀▀▀▀▀▀▀ ██  ██████
   ██ ██████████ ██      ██ ██████████ ██   ▀██▀
   ██ ██      ██ ██████  ██ ██      ██ ██    ██
   ██ ██████  ██ █████  ███ ██████  ██ ████▄ ██
   ██ █████  ███ ████  ████ █████  ███ ████████
   ██ ████  ████ ██████████ ████  ████ ████▀
   ██ ██████████ ▄▄▄▄▄▄▄▄▄▄ ██████████ ██
   ██            ▀▀▀▀▀▀▀▀▀▀            ██ 
   ▀█████████▀ ▄████████████▄ ▀█████████▀
  ▄▄▄▄▄▄▄▄▄▄▄▄███  ██  ██  ███▄▄▄▄▄▄▄▄▄▄▄▄
 ██████████████████████████████████████████
▄▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▄
█  ▄▀▄             █▀▀█▀▄▄
█  █▀█             █  ▐  ▐▌
█       ▄██▄       █  ▌  █
█     ▄██████▄     █  ▌ ▐▌
█    ██████████    █ ▐  █
█   ▐██████████▌   █ ▐ ▐▌
█    ▀▀██████▀▀    █ ▌ █
█     ▄▄▄██▄▄▄     █ ▌▐▌
█                  █▐ █
█                  █▐▐▌
█                  █▐█
▀▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▀█
▄▄█████████▄▄
▄██▀▀▀▀█████▀▀▀▀██▄
▄█▀       ▐█▌       ▀█▄
██         ▐█▌         ██
████▄     ▄█████▄     ▄████
████████▄███████████▄████████
███▀    █████████████    ▀███
██       ███████████       ██
▀█▄       █████████       ▄█▀
▀█▄    ▄██▀▀▀▀▀▀▀██▄  ▄▄▄█▀
▀███████         ███████▀
▀█████▄       ▄█████▀
▀▀▀███▄▄▄███▀▀▀
..PLAY NOW..
gentlemand
Legendary
*
Offline Offline

Activity: 2590
Merit: 3013


Welt Am Draht


View Profile
September 16, 2020, 10:48:52 AM
 #7

A nice little litmus test of the competence and vigilance of the developers who are using the same basis for other coins. My bet is that hardly any of them will care or understand nor will their handful of users. There'll be shitcoins with gaping vulnerabilities that were long ago dealt with on the better run platforms.
bbc.reporter
Legendary
*
Offline Offline

Activity: 2926
Merit: 1444



View Profile
September 17, 2020, 04:39:54 AM
 #8

This is very old news and the bug was fixed already. What is the writer of the article doing by putting this back on the surface again? I am skeptical, however, I do speculate that there are people behind this.

███████████████████████████
███████▄████████████▄██████
████████▄████████▄████████
███▀█████▀▄███▄▀█████▀███
█████▀█▀▄██▀▀▀██▄▀█▀█████
███████▄███████████▄███████
███████████████████████████
███████▀███████████▀███████
████▄██▄▀██▄▄▄██▀▄██▄████
████▄████▄▀███▀▄████▄████
██▄███▀▀█▀██████▀█▀███▄███
██▀█▀████████████████▀█▀███
███████████████████████████
.
.Duelbits.
..........UNLEASH..........
THE ULTIMATE
GAMING EXPERIENCE
DUELBITS
FANTASY
SPORTS
████▄▄█████▄▄
░▄████
███████████▄
▐███
███████████████▄
███
████████████████
███
████████████████▌
███
██████████████████
████████████████▀▀▀
███████████████▌
███████████████▌
████████████████
████████████████
████████████████
████▀▀███████▀▀
.
▬▬
VS
▬▬
████▄▄▄█████▄▄▄
░▄████████████████▄
▐██████████████████▄
████████████████████
████████████████████▌
█████████████████████
███████████████████
███████████████▌
███████████████▌
████████████████
████████████████
████████████████
████▀▀███████▀▀
/// PLAY FOR  FREE  ///
WIN FOR REAL
..PLAY NOW..
Harlot
Hero Member
*****
Offline Offline

Activity: 1806
Merit: 671


View Profile
September 27, 2020, 08:07:12 PM
 #9

This is very old news and the bug was fixed already. What is the writer of the article doing by putting this back on the surface again? I am skeptical, however, I do speculate that there are people behind this.

According to the article this bug only re-emerge because the vulnerability that the had found on Bitcoin was also seen on another cryptocurrency named Decred which I think is the reason why they also have revealed that they saw it on Bitcoin earlier because Decred was based on an older version of the Bitcoin code. Other cryptocurrencies that are also based on Bitcoin's code are also vulnerable and maybe that is why they came out of it to make the developers be able to handle the issue for their own respective projects.
bbc.reporter
Legendary
*
Offline Offline

Activity: 2926
Merit: 1444



View Profile
September 28, 2020, 02:21:59 AM
 #10

@Harlot. However, the title of the article is clickbait that implies something else. I am shaking my head on why many mainstream news outlets have the need to do something like this.

███████████████████████████
███████▄████████████▄██████
████████▄████████▄████████
███▀█████▀▄███▄▀█████▀███
█████▀█▀▄██▀▀▀██▄▀█▀█████
███████▄███████████▄███████
███████████████████████████
███████▀███████████▀███████
████▄██▄▀██▄▄▄██▀▄██▄████
████▄████▄▀███▀▄████▄████
██▄███▀▀█▀██████▀█▀███▄███
██▀█▀████████████████▀█▀███
███████████████████████████
.
.Duelbits.
..........UNLEASH..........
THE ULTIMATE
GAMING EXPERIENCE
DUELBITS
FANTASY
SPORTS
████▄▄█████▄▄
░▄████
███████████▄
▐███
███████████████▄
███
████████████████
███
████████████████▌
███
██████████████████
████████████████▀▀▀
███████████████▌
███████████████▌
████████████████
████████████████
████████████████
████▀▀███████▀▀
.
▬▬
VS
▬▬
████▄▄▄█████▄▄▄
░▄████████████████▄
▐██████████████████▄
████████████████████
████████████████████▌
█████████████████████
███████████████████
███████████████▌
███████████████▌
████████████████
████████████████
████████████████
████▀▀███████▀▀
/// PLAY FOR  FREE  ///
WIN FOR REAL
..PLAY NOW..
slaman29
Legendary
*
Offline Offline

Activity: 2646
Merit: 1212


Livecasino, 20% cashback, no fuss payouts.


View Profile
September 28, 2020, 10:03:36 AM
 #11

Is there some kind of reward for people to receive if they find vulnerabilities like this? Who would be funding such a reward, if it does exist?  I know exchanges and wallet providers will offer a reward, if someone finds an exploit in their code, but we know where they get there funds from.  Wink

Interesting question too. I know most blockchain projects have a bug bounty set aside from their own funds but those are all centralized ones. I guess Bitcoin doesn't have it maybe because it's just all these guys who are paid or volunteered to fix it at their own time. Probably why it takes 2 years to fix;)

██
██
██
██
██
██
██
██
██
██
██
██
██
... LIVECASINO.io    Play Live Games with up to 20% cashback!...██
██
██
██
██
██
██
██
██
██
██
██
██
bbc.reporter
Legendary
*
Offline Offline

Activity: 2926
Merit: 1444



View Profile
September 29, 2020, 12:48:51 AM
 #12

@slaman29, @Kakmakr. Bug bounties have never existed in many opensource projects unless someone organizes this for them.

Also, agreed! Good question because what are the trying hard influencers in the B Foundation doing about this? They only want influence with no effort? I reckon organizing a bug bounty should be their job.

███████████████████████████
███████▄████████████▄██████
████████▄████████▄████████
███▀█████▀▄███▄▀█████▀███
█████▀█▀▄██▀▀▀██▄▀█▀█████
███████▄███████████▄███████
███████████████████████████
███████▀███████████▀███████
████▄██▄▀██▄▄▄██▀▄██▄████
████▄████▄▀███▀▄████▄████
██▄███▀▀█▀██████▀█▀███▄███
██▀█▀████████████████▀█▀███
███████████████████████████
.
.Duelbits.
..........UNLEASH..........
THE ULTIMATE
GAMING EXPERIENCE
DUELBITS
FANTASY
SPORTS
████▄▄█████▄▄
░▄████
███████████▄
▐███
███████████████▄
███
████████████████
███
████████████████▌
███
██████████████████
████████████████▀▀▀
███████████████▌
███████████████▌
████████████████
████████████████
████████████████
████▀▀███████▀▀
.
▬▬
VS
▬▬
████▄▄▄█████▄▄▄
░▄████████████████▄
▐██████████████████▄
████████████████████
████████████████████▌
█████████████████████
███████████████████
███████████████▌
███████████████▌
████████████████
████████████████
████████████████
████▀▀███████▀▀
/// PLAY FOR  FREE  ///
WIN FOR REAL
..PLAY NOW..
gentlemand
Legendary
*
Offline Offline

Activity: 2590
Merit: 3013


Welt Am Draht


View Profile
September 30, 2020, 09:54:35 AM
 #13

I would assume they assume that protecting Bitcoin itself is enough of a bug bounty. If you find a gaping hole it's likely you own some and don't want it flying down the toilet.
Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!