summaryrefslogtreecommitdiff
path: root/16/e84b422a5aa581ca04f0766a1c68cf957f8f81
blob: bbe288bd3a86e9203db15b568dceed90291fbdd7 (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
Delivery-date: Wed, 03 Jul 2024 18:13:22 -0700
Received: from mail-yb1-f187.google.com ([209.85.219.187])
	by mail.fairlystable.org with esmtps  (TLS1.3) tls TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256
	(Exim 4.94.2)
	(envelope-from <bitcoindev+bncBC5P5KEHZQLBBKPOS62AMGQELGYJTBQ@googlegroups.com>)
	id 1sPB2H-0005yg-Ri
	for bitcoindev@gnusha.org; Wed, 03 Jul 2024 18:13:22 -0700
Received: by mail-yb1-f187.google.com with SMTP id 3f1490d57ef6-e03623b24ddsf214640276.1
        for <bitcoindev@gnusha.org>; Wed, 03 Jul 2024 18:13:21 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
        d=googlegroups.com; s=20230601; t=1720055595; x=1720660395; darn=gnusha.org;
        h=list-unsubscribe:list-subscribe:list-archive:list-help:list-post
         :list-id:mailing-list:precedence:x-original-sender:mime-version
         :subject:references:in-reply-to:message-id:to:from:date:sender:from
         :to:cc:subject:date:message-id:reply-to;
        bh=/f49indMlU9Azixhxw7OUeAUa7PmRtjV/KGJa9uz8Js=;
        b=ZYdC/7ZYiCDsFSH/qJrXatE7LK74G7F6aO5whZDr65CRbN06dlHEwQO/6wrvFgMHPk
         AmRGT3F103rq44fYyR1L2Gki9Q+qUs4zm23R6CpViwZA8EpN01X/GRXyDABGXFJGDwf2
         G6vPgFv5mi6OmGUumZNmwP2UnUEFdXDz3z8MM/+32iUrU07bGvyOJ4lvNr+8QOoe7J6S
         AydmbgKOAct2BZ27aB047pPzvZm11TiA/ooB8pljKggLVFdAbM/HbeCIjmOqneySyahm
         VjpCzIccqKTr2CqWKHnhBpdK9tqMa1S+7HNcDvKtrlEpCnYYIOBg0aPdqI/0BCrdkApF
         PQMw==
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
        d=googlegroups-com.20230601.gappssmtp.com; s=20230601; t=1720055595; x=1720660395; darn=gnusha.org;
        h=list-unsubscribe:list-subscribe:list-archive:list-help:list-post
         :list-id:mailing-list:precedence:x-original-sender:mime-version
         :subject:references:in-reply-to:message-id:to:from:date:from:to:cc
         :subject:date:message-id:reply-to;
        bh=/f49indMlU9Azixhxw7OUeAUa7PmRtjV/KGJa9uz8Js=;
        b=TakojERirPnvJ767hvNz6X9RTi9bm2rNIDdhXFy+w6hECHN9FvhTzNbYDMUEnycaJn
         5Xmn6WQMRF9CdUaQ+KQN5eSv1zlPr3CTMIpv7AK29WwQPS1jUqRb8jhyy7Fn2xZajplb
         JnE28XkheNhGeSOMHq95AEr25moj/8etWRp+VqO8qR1fGcE/+YfvuIJ8R5ZEt2yFXW2E
         /yFV3atLssSqbS25yShT9NXvlwmIOa5v+evOXVwOYLDpoJ+HUYDLul7hiU6D9N8+we5Z
         jHu/whRUI8dJXQ9yVDKUK5Hj+lCrlvqZ8/EpekYj5p9H/tYE3qPSwP4OUCkoVJiNNDeE
         MbMg==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
        d=1e100.net; s=20230601; t=1720055595; x=1720660395;
        h=list-unsubscribe:list-subscribe:list-archive:list-help:list-post
         :list-id:mailing-list:precedence:x-original-sender:mime-version
         :subject:references:in-reply-to:message-id:to:from:date:x-beenthere
         :x-gm-message-state:sender:from:to:cc:subject:date:message-id
         :reply-to;
        bh=/f49indMlU9Azixhxw7OUeAUa7PmRtjV/KGJa9uz8Js=;
        b=h31jBaNk1dLVVnfkOgHrPzAuC2bgEl9pb5cE1/SDAyxnKm23mcFmjmw29yTQUku09f
         QsBinvNqtbahyYJ8516YCtSCLM2sTmxRLSIhVYvWzoTEXgVh1KxXFiWuNOhovRnNfAEb
         hTAii1Ql+y7neVEdOuE6t5VBtbr4iJDUX42rMill11t1vL82l8jAS4ZljWJBDrLuV05d
         Kb9syBlfjjv26/2yXFZLeN+VImmU+cFhbMWtgz7CBSmkskQCDk6BHrpFpZXmNMjvaPUD
         vOz5ttGYH/5FwCNzSXISEaS7/4eQHNMr5rpGy3WyuKnT/QZFLJU0QTdJpQI96tNmTMKQ
         RpSg==
Sender: bitcoindev@googlegroups.com
X-Forwarded-Encrypted: i=1; AJvYcCV5gbVOEy3U7vHQ9ZWsY8wQDV7ulrYz/Xf/xY307h26LnqWwwMxgoSAQ3gaXiedIS2gla0tIM663uaQd8cR/traYFXUEsQ=
X-Gm-Message-State: AOJu0YxEq3OrzOb4+TROzz3jEI151teiCk/hs8M3albcBmKQ2I3CQNTC
	m708PkZMX1nByMh6C6vLOw4BmflyPowKUth7yB6xXDncqi+MUwX1
X-Google-Smtp-Source: AGHT+IF4C0HKzNOyUBw/RlQBWXbRgSpG5DzHjvgWpTkIt7HeXyDG01chWRL5iuUg3jUjCKNx7TA2KQ==
X-Received: by 2002:a25:ce44:0:b0:e03:af3d:d4be with SMTP id 3f1490d57ef6-e03c19faa7amr59395276.42.1720055595221;
        Wed, 03 Jul 2024 18:13:15 -0700 (PDT)
X-BeenThere: bitcoindev@googlegroups.com
Received: by 2002:a05:6902:18c6:b0:e03:62ce:ce8c with SMTP id
 3f1490d57ef6-e03bd143ea0ls233361276.2.-pod-prod-00-us; Wed, 03 Jul 2024
 18:13:13 -0700 (PDT)
X-Received: by 2002:a05:690c:3192:b0:651:2eea:4dfe with SMTP id 00721157ae682-6517da0915bmr215747b3.0.1720055593521;
        Wed, 03 Jul 2024 18:13:13 -0700 (PDT)
Received: by 2002:a05:690c:2c0e:b0:627:7f59:2eee with SMTP id 00721157ae682-6514347c5d4ms7b3;
        Wed, 3 Jul 2024 17:44:48 -0700 (PDT)
X-Received: by 2002:a0d:ebca:0:b0:61b:1dbf:e3f with SMTP id 00721157ae682-652d5c0834fmr17267b3.4.1720053887982;
        Wed, 03 Jul 2024 17:44:47 -0700 (PDT)
Date: Wed, 3 Jul 2024 17:44:47 -0700 (PDT)
From: Eric Voskuil <eric@voskuil.org>
To: Bitcoin Development Mailing List <bitcoindev@googlegroups.com>
Message-Id: <a9f31b7f-08c9-4ee0-97a0-1c8708ad5c63n@googlegroups.com>
In-Reply-To: <rALfxJ5b5hyubGwdVW3F4jtugxnXRvc-tjD_qwW7z73rd5j7lXGNdEHWikmSdmNG3vkSOIwEryZzOZr_DgmVDDmt9qsX0gpRAcpY9CfwSk4=@protonmail.com>
References: <rALfxJ5b5hyubGwdVW3F4jtugxnXRvc-tjD_qwW7z73rd5j7lXGNdEHWikmSdmNG3vkSOIwEryZzOZr_DgmVDDmt9qsX0gpRAcpY9CfwSk4=@protonmail.com>
Subject: [bitcoindev] Re: Bitcoin Core Security Disclosure Policy
MIME-Version: 1.0
Content-Type: multipart/mixed; 
	boundary="----=_Part_257617_667154445.1720053887747"
X-Original-Sender: eric@voskuil.org
Precedence: list
Mailing-list: list bitcoindev@googlegroups.com; contact bitcoindev+owners@googlegroups.com
List-ID: <bitcoindev.googlegroups.com>
X-Google-Group-Id: 786775582512
List-Post: <https://groups.google.com/group/bitcoindev/post>, <mailto:bitcoindev@googlegroups.com>
List-Help: <https://groups.google.com/support/>, <mailto:bitcoindev+help@googlegroups.com>
List-Archive: <https://groups.google.com/group/bitcoindev
List-Subscribe: <https://groups.google.com/group/bitcoindev/subscribe>, <mailto:bitcoindev+subscribe@googlegroups.com>
List-Unsubscribe: <mailto:googlegroups-manage+786775582512+unsubscribe@googlegroups.com>,
 <https://groups.google.com/group/bitcoindev/subscribe>
X-Spam-Score: -0.7 (/)

------=_Part_257617_667154445.1720053887747
Content-Type: multipart/alternative; 
	boundary="----=_Part_257618_1264436344.1720053887747"

------=_Part_257618_1264436344.1720053887747
Content-Type: text/plain; charset="UTF-8"

> The project has historically done a poor job at publicly disclosing 
security-critical bugs, whether externally reported or found by 
contributors. This has led to a situation where a lot of users perceive 
Bitcoin Core as never having bugs. This perception is dangerous and, 
unfortunately, not accurate.

I have to say this is one of the most compelling statements I've seen from 
the bitcoind/Bitcoin Core team in over 10 years. Many other projects have 
been on the receiving end of this misperception, and it has in fact caused 
material harm to the community. I don't know what precipitated this change, 
but props to you all for stepping up.

Best,
Eric

-- 
You received this message because you are subscribed to the Google Groups "Bitcoin Development Mailing List" group.
To unsubscribe from this group and stop receiving emails from it, send an email to bitcoindev+unsubscribe@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/bitcoindev/a9f31b7f-08c9-4ee0-97a0-1c8708ad5c63n%40googlegroups.com.

------=_Part_257618_1264436344.1720053887747
Content-Type: text/html; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

&gt; The project has historically done a poor job at publicly disclosing se=
curity-critical bugs, whether externally reported or found by contributors.=
 This has led to a situation where a lot of users perceive Bitcoin Core as =
never having bugs. This perception is dangerous and, unfortunately, not acc=
urate.<br /><br />I have to say this is one of the most compelling statemen=
ts I've seen from the bitcoind/Bitcoin Core team in over 10 years. Many oth=
er projects have been on the receiving end of this misperception, and it ha=
s in fact caused material harm to the community. I don't know what precipit=
ated this change, but props to you all for stepping up.<br /><br />Best,<di=
v>Eric</div>

<p></p>

-- <br />
You received this message because you are subscribed to the Google Groups &=
quot;Bitcoin Development Mailing List&quot; group.<br />
To unsubscribe from this group and stop receiving emails from it, send an e=
mail to <a href=3D"mailto:bitcoindev+unsubscribe@googlegroups.com">bitcoind=
ev+unsubscribe@googlegroups.com</a>.<br />
To view this discussion on the web visit <a href=3D"https://groups.google.c=
om/d/msgid/bitcoindev/a9f31b7f-08c9-4ee0-97a0-1c8708ad5c63n%40googlegroups.=
com?utm_medium=3Demail&utm_source=3Dfooter">https://groups.google.com/d/msg=
id/bitcoindev/a9f31b7f-08c9-4ee0-97a0-1c8708ad5c63n%40googlegroups.com</a>.=
<br />

------=_Part_257618_1264436344.1720053887747--

------=_Part_257617_667154445.1720053887747--