Bitcoin [BTC] Developer Discovers Vulnerability In Bitcoin Cash [BCH] Code, Finds It Near Impossible to Report the Bug to Developers

Bitcoin [BTC] Developer Discovers Vulnerability In Bitcoin Cash [BCH] Code, Finds It Near Impossible to Report the Bug to Developers
ôîòî ïîêàçàíî ñ : blokt.com

2018-8-10 12:02

On Thursday, August 9, a developer and researcher in the crypto industry detailed the difficulties he had communicating a vulnerability in the Bitcoin Cash protocol to their dev team. Cory Fields from the Digital Currency Initiative at MIT Media Lab in Massachusetts outlined the issue in a post on his Medium blog. The bug was successfully resolved only after a lot of trouble on Fields’ part, which he wanted to address publicly with the intention of raising awareness about the importance of open and speedy bug reporting avenues for every cryptocurrency.

Chain-splitting Vulnerability

Fields explained that “a portion of the transaction signature verification code was rewritten, but the new code omitted a critical check of a specific bit in the signature type. I refer to that bit in the disclosure as SIGHASH_BUG. This omission would have allowed a specially crafted transaction to split the Bitcoin Cash blockchain into two incompatible chains.”

He added:

“There were no keys listed for any of the lead developers on the public PGP key servers where they would usually be found, and there were none present in their code repository either. At that point, I had no option other than to request keys anonymously through different online channels, using Tor to mask my identity as much as possible.”

He wanted to submit the vulnerability anonymously since identifying oneself leaves the possibility of being accused of any exploits that might occur. He tried to announce it to the Bitcoin Cash devs on GitHub to no avail and had extreme difficulty finding a public key for any of the devs to notify them with an encrypted message (since any open communication could be seized upon by attackers).

Slow Resolution

Eventually, the bug was addressed:

“On April 27, after waiting roughly 48 hours for a response to the disclosure, a pull request was opened to covertly fixed the issue in Bitcoin ABC.”

The issue draws attention to the sometimes disorganized nature of the crypto community at a time when increasing regulatory spotlight is being shone on the industry. Furthermore, the Bitcoin Cash project has come under fire for suspect and hostile working methods, which this episode is likely to compound in the eyes of the wider public.

Bitcoin [BTC] Developer Discovers Vulnerability In Bitcoin Cash [BCH] Code, Finds It Near Impossible to Report the Bug to Developers was originally found on [blokt] - Blockchain, Bitcoin & Cryptocurrency News.

Similar to Notcoin - TapSwap on Solana Airdrops In 2024

origin »

Bitcoin (BTC) íà Currencies.ru

$ 61885.95 (+0.05%)
Îáúåì 24H $28.018b
Èçìåíåèÿ 24h: -1.61 %, 7d: -2.05 %
Cåãîäíÿ L: $61277.49 - H: $63088.03
Êàïèòàëèçàöèÿ $1221.085b Rank 1
Öåíà â ÷àñ íîâîñòè $ 6405.81 (866.09%)

bitcoin bug developer cash vulnerability developers impossible

bitcoin bug → Ðåçóëüòàòîâ: 10


Ôîòî:

Kraken bug apparently let users buy Bitcoin for $8,000 and instantly sell it for $12,000

Cryptocurrency exchange Kraken – one of the world’s oldest – has disclosed a bug that apparently allowed certain customers to purchase Bitcoin at $8,000 and sell it for $12,000. Taking to Twitter, the exchange said “a test of an unreleased advanced order type encountered a bug, which resulted in the order’s prices being matched against the wrong side of the book.

2019-9-16 18:31


Ôîòî:

John Newbery: I’m Responsible For ‘Worst Bitcoin Bug Since 2010’

Bitcoin Core developers have decried infighting between Bitcoin (BTC) and Bitcoin Cash (BCH) supporters after John Newbery claimed responsibility for last week’s CVE-2018-17144 network bug. ‘Embarrassed And Sorry’ In comments on Twitter September 23, Newbery, who is tasked with checking the Bitcoin codebase, said it was because of him that the bug had gone unnoticed.

2018-9-24 14:00


Ôîòî:

The Genesis Files: With Bit Gold, Szabo Was Inches Away From Inventing Bitcoin

As his Hungarian parents had fled post-war Soviet regime to settle in the United States, Nick Szabo came to call the Californian Bay area of the 1990s his home. Here, he was among the first to frequent the in-person “Cypherpunk” meetings organized by Timothy May, Eric Hughes and other founding members of the collective of cryptographers, programmers and privacy activists centered around the ’90s mailing list of the same name.

2018-7-13 17:16