• Contact Us
  • Privacy Policy
  • Terms of Use
  • DMCA
  • Disclaimer
Sunday, July 7, 2024
CryptoBangs.com
Advertisement
  • Home
  • Live Crypto Prices
  • Crypto News
    • Bitcoin
    • Ethereum
    • Ripple
    • Altcoin
    • NFT News
  • DeFi
  • Blockchain
  • Regulation
  • Shop
  • Blog
  • Calculator
No Result
View All Result
  • Home
  • Live Crypto Prices
  • Crypto News
    • Bitcoin
    • Ethereum
    • Ripple
    • Altcoin
    • NFT News
  • DeFi
  • Blockchain
  • Regulation
  • Shop
  • Blog
  • Calculator
No Result
View All Result
CryptoBangs.com
No Result
View All Result

Bitcoin Core Announces New Security Disclosure Policy

July 3, 2024
in Bitcoin
Reading Time: 3 mins read
A A
Bitcoin Core Announces New Security Disclosure Policy
ShareShareShareShareShare

A group of Bitcoin Core developers has introduced a comprehensive security disclosure policy to address past shortcomings in publicizing security-critical bugs.

Related articles

North Carolina Governor Vetoes Bill Banning State Use of Central Bank Digital Currencies

North Carolina Governor Vetoes Bill Banning State Use of Central Bank Digital Currencies

July 7, 2024
Bitcoin Woes Not Over? Analyst Predicts Further Crash To $47,000

Bitcoin Woes Not Over? Analyst Predicts Further Crash To $47,000

July 6, 2024

This new policy aims to establish a standardized process for reporting and disclosing vulnerabilities, thereby improving transparency and security within the Bitcoin ecosystem.

Several previously undisclosed vulnerabilities are also included with the announcement.

What is a Security Disclosure?

A security disclosure is a process through which security researchers or ethical hackers report vulnerabilities they discover in software or systems to the affected organization. The goal is to allow the organization to address these vulnerabilities before they can be exploited by malicious actors. This process typically involves discovering the vulnerability, reporting it confidentially, verifying its existence, developing a fix, and finally, publicly disclosing the vulnerability along with details and mitigation advice.

Should Users Be Worried?

The latest Bitcoin Core security disclosures address various vulnerabilities with varying severity. Key issues include multiple denial-of-service (DoS) vulnerabilities that could cause service disruptions, a remote code execution (RCE) flaw in the miniUPnPc library, transaction handling bugs that could lead to censorship or improper orphan transaction management, and network vulnerabilities such as buffer blowup and timestamp overflow leading to network splits.

It is not believed any of those vulnerabilities currently present a critical risk for the Bitcoin network. Regardless, users are strongly encouraged to ensure their software is up to date.

For detailed information, see the commits on GitHub: Bitcoin Core Security Disclosures.

Improving the disclosure process

Bitcoin Core’s new policy categorizes vulnerabilities into four severity levels: Low, Medium, High, and Critical.

  • Low severity: Bugs that are difficult to exploit or have minimal impact. These will be disclosed two weeks after a fix is released.
  • Medium and High severity: Bugs with significant impact or moderate ease of exploitation. These will be disclosed a year after the last affected release goes end-of-life (EOL).
  • Critical severity: Bugs that threaten the entire network’s integrity, such as inflation or coin theft vulnerabilities, will be handled with ad-hoc procedures due to their severe nature.

This policy aims to provide consistent tracking and standardized disclosure processes, encouraging responsible reporting and allowing the community to address issues promptly.

History of CVE Disclosures in Bitcoin

Bitcoin has experienced several notable security issues, known as CVEs (Common Vulnerabilities and Exposures), over the years. These incidents highlight the importance of vigilant security practices and timely updates. Here are some key examples:

CVE-2012-2459: This critical bug could cause network problems by allowing attackers to create invalid blocks that looked valid, potentially splitting the Bitcoin network temporarily. It was fixed in Bitcoin Core version 0.6.1 and motivated further improvements in Bitcoin’s security protocols​.

CVE-2018-17144: A critical bug that could have allowed attackers to create extra Bitcoins, violating the fixed supply principle. This issue was discovered and fixed in September 2018. Users needed to update their software to avoid potential exploitation​

Additionally, the Bitcoin community has discussed various other vulnerabilities and potential fixes that have not yet been implemented.

CVE-2013-2292: By creating blocks that take a very long time to verify, an attacker could significantly slow down the network.

CVE-2017-12842: This vulnerability can trick lightweight Bitcoin wallets into thinking they received a payment when they hadn’t. This is risky for SPV (Simplified Payment Verification) clients.

The conversation around these vulnerabilities underscores the ongoing need for coordinated and community-supported updates to Bitcoin’s protocol. Ongoing research around the idea of a consensus cleanup soft fork seeks to address latent vulnerabilities in a unified and efficient manner, ensuring the continued robustness and security of the Bitcoin network.

Maintaining software security is a dynamic process requiring ongoing vigilance and updates. This intersects with the broader debate on Bitcoin ossification—where the core protocol remains unchanged to maintain stability and trust. While some advocate for minimal changes to avoid risks, others argue that occasional updates are necessary to enhance security and functionality.

This new disclosure policy by Bitcoin Core is a step towards balancing these perspectives by ensuring that any necessary updates are well-communicated and managed responsibly.

Credit: Source link

ShareTweetSendPinShare
Previous Post

Open Campus Secures Arbitrum Foundation Grant to Launch EDU Chain for Education

Next Post

Can Pepe Coin [PEPE] Erase a Zero This July 2024?

Related Posts

North Carolina Governor Vetoes Bill Banning State Use of Central Bank Digital Currencies

North Carolina Governor Vetoes Bill Banning State Use of Central Bank Digital Currencies

July 7, 2024

The governor of the U.S. state of North Carolina has vetoed House Bill 690, which seeks to ban state payments...

Bitcoin Woes Not Over? Analyst Predicts Further Crash To $47,000

Bitcoin Woes Not Over? Analyst Predicts Further Crash To $47,000

July 6, 2024

Although Bitcoin has reclaimed the $56,000 price level in the past few hours, its sudden drop below $54,000 on July...

Solana Bounces Back After Failing To Break $118 Support – Time To Buy?

Solana Bounces Back After Failing To Break $118 Support – Time To Buy?

July 6, 2024

Solana (SOL) recently experienced a price pullback after failing to break below the crucial $118 support level. This rebound indicates...

Chainlink Loses 10%, Further Drop To $6.80 Feared

Chainlink Loses 10%, Further Drop To $6.80 Feared

July 6, 2024

The cryptocurrency market continues its summer swoon, with major coins like Bitcoin tumbling to four-month lows. Chainlink (LINK), a key...

Tangem Partners With Visa to Launch Self-Custodial Crypto Payment Card

Tangem Partners With Visa to Launch Self-Custodial Crypto Payment Card

July 6, 2024

Hardware wallet firm Tangem AG is collaborating with Visa to launch a self-custodial payment solution. This collaboration introduces a Visa...

Load More
Next Post
Can Pepe Coin [PEPE] Erase a Zero This July 2024?

Can Pepe Coin [PEPE] Erase a Zero This July 2024?

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Vitalik Buterin suggests ways to speed up Ethereum transaction confirmations

Vitalik Buterin suggests ways to speed up Ethereum transaction confirmations

July 1, 2024
Court Rules Against DraftKings NFTs Case

Court Rules Against DraftKings NFTs Case

July 4, 2024
German Government Moves Over $75 Million in Bitcoin to Exchanges

German Government Moves Over $75 Million in Bitcoin to Exchanges

July 4, 2024
Standard Chartered Predicts Bitcoin Price Could Reach $100,000

Standard Chartered Predicts Bitcoin Price Could Reach $100,000

July 3, 2024
Get Ready for the Moonray Airdrop: Everything You Need to Know

Get Ready for the Moonray Airdrop: Everything You Need to Know

July 1, 2024
CryptoBangs.com

CryptoBangs.com is an online news portal that aims to share the latest crypto news, bitcoin, altcoin, blockchain, nft news and much more stuff like that.

What’s New Here!

  • Crypto Weekly Roundup: Market Crashes, Justin Sun Offers Help To Stop The Bleed, & More
  • Notcoin Soars in Popularity Amid Crypto Market Recovery
  • North Carolina Governor Vetoes Bill Banning State Use of Central Bank Digital Currencies
  • Bitcoin Woes Not Over? Analyst Predicts Further Crash To $47,000

Newsletter

Don't miss a beat and stay up to date with our Newsletter!
Loading

  • Contact Us
  • Privacy Policy
  • Terms of Use
  • DMCA
  • Disclaimer

© 2023 - CryptoBangs.com - All Rights Reserved!

No Result
View All Result
  • Home
  • Live Crypto Prices
  • Crypto News
    • Bitcoin
    • Ethereum
    • Ripple
    • Altcoin
    • NFT News
  • DeFi
  • Blockchain
  • Regulation
  • Shop
  • Blog
  • Calculator

© 2018 JNews by Jegtheme.

You have not selected any currencies to display
WP Twitter Auto Publish Powered By : XYZScripts.com