Delivery-date: Wed, 03 Jul 2024 18:13:22 -0700 Received: from mail-yb1-f187.google.com ([209.85.219.187]) by mail.fairlystable.org with esmtps (TLS1.3) tls TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 (Exim 4.94.2) (envelope-from ) id 1sPB2H-0005yg-Ri for bitcoindev@gnusha.org; Wed, 03 Jul 2024 18:13:22 -0700 Received: by mail-yb1-f187.google.com with SMTP id 3f1490d57ef6-e03623b24ddsf214640276.1 for ; Wed, 03 Jul 2024 18:13:21 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=googlegroups.com; s=20230601; t=1720055595; x=1720660395; darn=gnusha.org; h=list-unsubscribe:list-subscribe:list-archive:list-help:list-post :list-id:mailing-list:precedence:x-original-sender:mime-version :subject:references:in-reply-to:message-id:to:from:date:sender:from :to:cc:subject:date:message-id:reply-to; bh=/f49indMlU9Azixhxw7OUeAUa7PmRtjV/KGJa9uz8Js=; b=ZYdC/7ZYiCDsFSH/qJrXatE7LK74G7F6aO5whZDr65CRbN06dlHEwQO/6wrvFgMHPk AmRGT3F103rq44fYyR1L2Gki9Q+qUs4zm23R6CpViwZA8EpN01X/GRXyDABGXFJGDwf2 G6vPgFv5mi6OmGUumZNmwP2UnUEFdXDz3z8MM/+32iUrU07bGvyOJ4lvNr+8QOoe7J6S AydmbgKOAct2BZ27aB047pPzvZm11TiA/ooB8pljKggLVFdAbM/HbeCIjmOqneySyahm VjpCzIccqKTr2CqWKHnhBpdK9tqMa1S+7HNcDvKtrlEpCnYYIOBg0aPdqI/0BCrdkApF PQMw== DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=googlegroups-com.20230601.gappssmtp.com; s=20230601; t=1720055595; x=1720660395; darn=gnusha.org; h=list-unsubscribe:list-subscribe:list-archive:list-help:list-post :list-id:mailing-list:precedence:x-original-sender:mime-version :subject:references:in-reply-to:message-id:to:from:date:from:to:cc :subject:date:message-id:reply-to; bh=/f49indMlU9Azixhxw7OUeAUa7PmRtjV/KGJa9uz8Js=; b=TakojERirPnvJ767hvNz6X9RTi9bm2rNIDdhXFy+w6hECHN9FvhTzNbYDMUEnycaJn 5Xmn6WQMRF9CdUaQ+KQN5eSv1zlPr3CTMIpv7AK29WwQPS1jUqRb8jhyy7Fn2xZajplb JnE28XkheNhGeSOMHq95AEr25moj/8etWRp+VqO8qR1fGcE/+YfvuIJ8R5ZEt2yFXW2E /yFV3atLssSqbS25yShT9NXvlwmIOa5v+evOXVwOYLDpoJ+HUYDLul7hiU6D9N8+we5Z jHu/whRUI8dJXQ9yVDKUK5Hj+lCrlvqZ8/EpekYj5p9H/tYE3qPSwP4OUCkoVJiNNDeE MbMg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1720055595; x=1720660395; h=list-unsubscribe:list-subscribe:list-archive:list-help:list-post :list-id:mailing-list:precedence:x-original-sender:mime-version :subject:references:in-reply-to:message-id:to:from:date:x-beenthere :x-gm-message-state:sender:from:to:cc:subject:date:message-id :reply-to; bh=/f49indMlU9Azixhxw7OUeAUa7PmRtjV/KGJa9uz8Js=; b=h31jBaNk1dLVVnfkOgHrPzAuC2bgEl9pb5cE1/SDAyxnKm23mcFmjmw29yTQUku09f QsBinvNqtbahyYJ8516YCtSCLM2sTmxRLSIhVYvWzoTEXgVh1KxXFiWuNOhovRnNfAEb hTAii1Ql+y7neVEdOuE6t5VBtbr4iJDUX42rMill11t1vL82l8jAS4ZljWJBDrLuV05d Kb9syBlfjjv26/2yXFZLeN+VImmU+cFhbMWtgz7CBSmkskQCDk6BHrpFpZXmNMjvaPUD vOz5ttGYH/5FwCNzSXISEaS7/4eQHNMr5rpGy3WyuKnT/QZFLJU0QTdJpQI96tNmTMKQ RpSg== Sender: bitcoindev@googlegroups.com X-Forwarded-Encrypted: i=1; AJvYcCV5gbVOEy3U7vHQ9ZWsY8wQDV7ulrYz/Xf/xY307h26LnqWwwMxgoSAQ3gaXiedIS2gla0tIM663uaQd8cR/traYFXUEsQ= X-Gm-Message-State: AOJu0YxEq3OrzOb4+TROzz3jEI151teiCk/hs8M3albcBmKQ2I3CQNTC m708PkZMX1nByMh6C6vLOw4BmflyPowKUth7yB6xXDncqi+MUwX1 X-Google-Smtp-Source: AGHT+IF4C0HKzNOyUBw/RlQBWXbRgSpG5DzHjvgWpTkIt7HeXyDG01chWRL5iuUg3jUjCKNx7TA2KQ== X-Received: by 2002:a25:ce44:0:b0:e03:af3d:d4be with SMTP id 3f1490d57ef6-e03c19faa7amr59395276.42.1720055595221; Wed, 03 Jul 2024 18:13:15 -0700 (PDT) X-BeenThere: bitcoindev@googlegroups.com Received: by 2002:a05:6902:18c6:b0:e03:62ce:ce8c with SMTP id 3f1490d57ef6-e03bd143ea0ls233361276.2.-pod-prod-00-us; Wed, 03 Jul 2024 18:13:13 -0700 (PDT) X-Received: by 2002:a05:690c:3192:b0:651:2eea:4dfe with SMTP id 00721157ae682-6517da0915bmr215747b3.0.1720055593521; Wed, 03 Jul 2024 18:13:13 -0700 (PDT) Received: by 2002:a05:690c:2c0e:b0:627:7f59:2eee with SMTP id 00721157ae682-6514347c5d4ms7b3; Wed, 3 Jul 2024 17:44:48 -0700 (PDT) X-Received: by 2002:a0d:ebca:0:b0:61b:1dbf:e3f with SMTP id 00721157ae682-652d5c0834fmr17267b3.4.1720053887982; Wed, 03 Jul 2024 17:44:47 -0700 (PDT) Date: Wed, 3 Jul 2024 17:44:47 -0700 (PDT) From: Eric Voskuil To: Bitcoin Development Mailing List Message-Id: In-Reply-To: References: Subject: [bitcoindev] Re: Bitcoin Core Security Disclosure Policy MIME-Version: 1.0 Content-Type: multipart/mixed; boundary="----=_Part_257617_667154445.1720053887747" X-Original-Sender: eric@voskuil.org Precedence: list Mailing-list: list bitcoindev@googlegroups.com; contact bitcoindev+owners@googlegroups.com List-ID: X-Google-Group-Id: 786775582512 List-Post: , List-Help: , List-Archive: , List-Unsubscribe: , X-Spam-Score: -0.7 (/) ------=_Part_257617_667154445.1720053887747 Content-Type: multipart/alternative; boundary="----=_Part_257618_1264436344.1720053887747" ------=_Part_257618_1264436344.1720053887747 Content-Type: text/plain; charset="UTF-8" > The project has historically done a poor job at publicly disclosing security-critical bugs, whether externally reported or found by contributors. This has led to a situation where a lot of users perceive Bitcoin Core as never having bugs. This perception is dangerous and, unfortunately, not accurate. I have to say this is one of the most compelling statements I've seen from the bitcoind/Bitcoin Core team in over 10 years. Many other projects have been on the receiving end of this misperception, and it has in fact caused material harm to the community. I don't know what precipitated this change, but props to you all for stepping up. Best, Eric -- You received this message because you are subscribed to the Google Groups "Bitcoin Development Mailing List" group. To unsubscribe from this group and stop receiving emails from it, send an email to bitcoindev+unsubscribe@googlegroups.com. To view this discussion on the web visit https://groups.google.com/d/msgid/bitcoindev/a9f31b7f-08c9-4ee0-97a0-1c8708ad5c63n%40googlegroups.com. ------=_Part_257618_1264436344.1720053887747 Content-Type: text/html; charset="UTF-8" Content-Transfer-Encoding: quoted-printable > The project has historically done a poor job at publicly disclosing se= curity-critical bugs, whether externally reported or found by contributors.= This has led to a situation where a lot of users perceive Bitcoin Core as = never having bugs. This perception is dangerous and, unfortunately, not acc= urate.

I have to say this is one of the most compelling statemen= ts I've seen from the bitcoind/Bitcoin Core team in over 10 years. Many oth= er projects have been on the receiving end of this misperception, and it ha= s in fact caused material harm to the community. I don't know what precipit= ated this change, but props to you all for stepping up.

Best,Eric

--
You received this message because you are subscribed to the Google Groups &= quot;Bitcoin Development Mailing List" group.
To unsubscribe from this group and stop receiving emails from it, send an e= mail to bitcoind= ev+unsubscribe@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msg= id/bitcoindev/a9f31b7f-08c9-4ee0-97a0-1c8708ad5c63n%40googlegroups.com.=
------=_Part_257618_1264436344.1720053887747-- ------=_Part_257617_667154445.1720053887747--