Responsible disclosures and Bitcoin development



Summary:

A developer has raised concerns over an open issue in the bitcoin core repository, which was created last week. The issue in question relates to CPU usage and it has been suggested that it should have been reported privately as a vulnerability, rather than being posted publicly on GitHub. While some users have also experienced similar issues without debug build used for bitcoind, there has been no noticeable decline in the number of listening nodes on bitnodes.io in the last 24 hours. However, it has been emphasised that if there is even a 1% possibility of something being a vulnerability, it should be reported privately. The email references a previous case where a vulnerability was reported publicly and subsequently exploited on mainnet, affecting some projects. Therefore, the developer is simply requesting that the impact of any vulnerabilities be considered, as even projects with no financial activity involved follow better practices. Some suggestions were made for users experiencing the CPU usage issue, such as running bitcoind with a bigger mempool or trying other things shared in the issue by everyone. The email was signed off by the self-proclaimed "floppy disk guy" using Proton Mail secure email.


Updated on: 2023-06-16T18:26:24.666359+00:00