1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
|
Delivery-date: Wed, 03 Jul 2024 18:13:22 -0700
Received: from mail-yb1-f187.google.com ([209.85.219.187])
by mail.fairlystable.org with esmtps (TLS1.3) tls TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256
(Exim 4.94.2)
(envelope-from <bitcoindev+bncBC5P5KEHZQLBBKPOS62AMGQELGYJTBQ@googlegroups.com>)
id 1sPB2H-0005yg-Ri
for bitcoindev@gnusha.org; Wed, 03 Jul 2024 18:13:22 -0700
Received: by mail-yb1-f187.google.com with SMTP id 3f1490d57ef6-e03623b24ddsf214640276.1
for <bitcoindev@gnusha.org>; Wed, 03 Jul 2024 18:13:21 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
d=googlegroups.com; s=20230601; t=1720055595; x=1720660395; darn=gnusha.org;
h=list-unsubscribe:list-subscribe:list-archive:list-help:list-post
:list-id:mailing-list:precedence:x-original-sender:mime-version
:subject:references:in-reply-to:message-id:to:from:date:sender:from
:to:cc:subject:date:message-id:reply-to;
bh=/f49indMlU9Azixhxw7OUeAUa7PmRtjV/KGJa9uz8Js=;
b=ZYdC/7ZYiCDsFSH/qJrXatE7LK74G7F6aO5whZDr65CRbN06dlHEwQO/6wrvFgMHPk
AmRGT3F103rq44fYyR1L2Gki9Q+qUs4zm23R6CpViwZA8EpN01X/GRXyDABGXFJGDwf2
G6vPgFv5mi6OmGUumZNmwP2UnUEFdXDz3z8MM/+32iUrU07bGvyOJ4lvNr+8QOoe7J6S
AydmbgKOAct2BZ27aB047pPzvZm11TiA/ooB8pljKggLVFdAbM/HbeCIjmOqneySyahm
VjpCzIccqKTr2CqWKHnhBpdK9tqMa1S+7HNcDvKtrlEpCnYYIOBg0aPdqI/0BCrdkApF
PQMw==
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
d=googlegroups-com.20230601.gappssmtp.com; s=20230601; t=1720055595; x=1720660395; darn=gnusha.org;
h=list-unsubscribe:list-subscribe:list-archive:list-help:list-post
:list-id:mailing-list:precedence:x-original-sender:mime-version
:subject:references:in-reply-to:message-id:to:from:date:from:to:cc
:subject:date:message-id:reply-to;
bh=/f49indMlU9Azixhxw7OUeAUa7PmRtjV/KGJa9uz8Js=;
b=TakojERirPnvJ767hvNz6X9RTi9bm2rNIDdhXFy+w6hECHN9FvhTzNbYDMUEnycaJn
5Xmn6WQMRF9CdUaQ+KQN5eSv1zlPr3CTMIpv7AK29WwQPS1jUqRb8jhyy7Fn2xZajplb
JnE28XkheNhGeSOMHq95AEr25moj/8etWRp+VqO8qR1fGcE/+YfvuIJ8R5ZEt2yFXW2E
/yFV3atLssSqbS25yShT9NXvlwmIOa5v+evOXVwOYLDpoJ+HUYDLul7hiU6D9N8+we5Z
jHu/whRUI8dJXQ9yVDKUK5Hj+lCrlvqZ8/EpekYj5p9H/tYE3qPSwP4OUCkoVJiNNDeE
MbMg==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
d=1e100.net; s=20230601; t=1720055595; x=1720660395;
h=list-unsubscribe:list-subscribe:list-archive:list-help:list-post
:list-id:mailing-list:precedence:x-original-sender:mime-version
:subject:references:in-reply-to:message-id:to:from:date:x-beenthere
:x-gm-message-state:sender:from:to:cc:subject:date:message-id
:reply-to;
bh=/f49indMlU9Azixhxw7OUeAUa7PmRtjV/KGJa9uz8Js=;
b=h31jBaNk1dLVVnfkOgHrPzAuC2bgEl9pb5cE1/SDAyxnKm23mcFmjmw29yTQUku09f
QsBinvNqtbahyYJ8516YCtSCLM2sTmxRLSIhVYvWzoTEXgVh1KxXFiWuNOhovRnNfAEb
hTAii1Ql+y7neVEdOuE6t5VBtbr4iJDUX42rMill11t1vL82l8jAS4ZljWJBDrLuV05d
Kb9syBlfjjv26/2yXFZLeN+VImmU+cFhbMWtgz7CBSmkskQCDk6BHrpFpZXmNMjvaPUD
vOz5ttGYH/5FwCNzSXISEaS7/4eQHNMr5rpGy3WyuKnT/QZFLJU0QTdJpQI96tNmTMKQ
RpSg==
Sender: bitcoindev@googlegroups.com
X-Forwarded-Encrypted: i=1; AJvYcCV5gbVOEy3U7vHQ9ZWsY8wQDV7ulrYz/Xf/xY307h26LnqWwwMxgoSAQ3gaXiedIS2gla0tIM663uaQd8cR/traYFXUEsQ=
X-Gm-Message-State: AOJu0YxEq3OrzOb4+TROzz3jEI151teiCk/hs8M3albcBmKQ2I3CQNTC
m708PkZMX1nByMh6C6vLOw4BmflyPowKUth7yB6xXDncqi+MUwX1
X-Google-Smtp-Source: AGHT+IF4C0HKzNOyUBw/RlQBWXbRgSpG5DzHjvgWpTkIt7HeXyDG01chWRL5iuUg3jUjCKNx7TA2KQ==
X-Received: by 2002:a25:ce44:0:b0:e03:af3d:d4be with SMTP id 3f1490d57ef6-e03c19faa7amr59395276.42.1720055595221;
Wed, 03 Jul 2024 18:13:15 -0700 (PDT)
X-BeenThere: bitcoindev@googlegroups.com
Received: by 2002:a05:6902:18c6:b0:e03:62ce:ce8c with SMTP id
3f1490d57ef6-e03bd143ea0ls233361276.2.-pod-prod-00-us; Wed, 03 Jul 2024
18:13:13 -0700 (PDT)
X-Received: by 2002:a05:690c:3192:b0:651:2eea:4dfe with SMTP id 00721157ae682-6517da0915bmr215747b3.0.1720055593521;
Wed, 03 Jul 2024 18:13:13 -0700 (PDT)
Received: by 2002:a05:690c:2c0e:b0:627:7f59:2eee with SMTP id 00721157ae682-6514347c5d4ms7b3;
Wed, 3 Jul 2024 17:44:48 -0700 (PDT)
X-Received: by 2002:a0d:ebca:0:b0:61b:1dbf:e3f with SMTP id 00721157ae682-652d5c0834fmr17267b3.4.1720053887982;
Wed, 03 Jul 2024 17:44:47 -0700 (PDT)
Date: Wed, 3 Jul 2024 17:44:47 -0700 (PDT)
From: Eric Voskuil <eric@voskuil.org>
To: Bitcoin Development Mailing List <bitcoindev@googlegroups.com>
Message-Id: <a9f31b7f-08c9-4ee0-97a0-1c8708ad5c63n@googlegroups.com>
In-Reply-To: <rALfxJ5b5hyubGwdVW3F4jtugxnXRvc-tjD_qwW7z73rd5j7lXGNdEHWikmSdmNG3vkSOIwEryZzOZr_DgmVDDmt9qsX0gpRAcpY9CfwSk4=@protonmail.com>
References: <rALfxJ5b5hyubGwdVW3F4jtugxnXRvc-tjD_qwW7z73rd5j7lXGNdEHWikmSdmNG3vkSOIwEryZzOZr_DgmVDDmt9qsX0gpRAcpY9CfwSk4=@protonmail.com>
Subject: [bitcoindev] Re: Bitcoin Core Security Disclosure Policy
MIME-Version: 1.0
Content-Type: multipart/mixed;
boundary="----=_Part_257617_667154445.1720053887747"
X-Original-Sender: eric@voskuil.org
Precedence: list
Mailing-list: list bitcoindev@googlegroups.com; contact bitcoindev+owners@googlegroups.com
List-ID: <bitcoindev.googlegroups.com>
X-Google-Group-Id: 786775582512
List-Post: <https://groups.google.com/group/bitcoindev/post>, <mailto:bitcoindev@googlegroups.com>
List-Help: <https://groups.google.com/support/>, <mailto:bitcoindev+help@googlegroups.com>
List-Archive: <https://groups.google.com/group/bitcoindev
List-Subscribe: <https://groups.google.com/group/bitcoindev/subscribe>, <mailto:bitcoindev+subscribe@googlegroups.com>
List-Unsubscribe: <mailto:googlegroups-manage+786775582512+unsubscribe@googlegroups.com>,
<https://groups.google.com/group/bitcoindev/subscribe>
X-Spam-Score: -0.7 (/)
------=_Part_257617_667154445.1720053887747
Content-Type: multipart/alternative;
boundary="----=_Part_257618_1264436344.1720053887747"
------=_Part_257618_1264436344.1720053887747
Content-Type: text/plain; charset="UTF-8"
> The project has historically done a poor job at publicly disclosing
security-critical bugs, whether externally reported or found by
contributors. This has led to a situation where a lot of users perceive
Bitcoin Core as never having bugs. This perception is dangerous and,
unfortunately, not accurate.
I have to say this is one of the most compelling statements I've seen from
the bitcoind/Bitcoin Core team in over 10 years. Many other projects have
been on the receiving end of this misperception, and it has in fact caused
material harm to the community. I don't know what precipitated this change,
but props to you all for stepping up.
Best,
Eric
--
You received this message because you are subscribed to the Google Groups "Bitcoin Development Mailing List" group.
To unsubscribe from this group and stop receiving emails from it, send an email to bitcoindev+unsubscribe@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/bitcoindev/a9f31b7f-08c9-4ee0-97a0-1c8708ad5c63n%40googlegroups.com.
------=_Part_257618_1264436344.1720053887747
Content-Type: text/html; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable
> The project has historically done a poor job at publicly disclosing se=
curity-critical bugs, whether externally reported or found by contributors.=
This has led to a situation where a lot of users perceive Bitcoin Core as =
never having bugs. This perception is dangerous and, unfortunately, not acc=
urate.<br /><br />I have to say this is one of the most compelling statemen=
ts I've seen from the bitcoind/Bitcoin Core team in over 10 years. Many oth=
er projects have been on the receiving end of this misperception, and it ha=
s in fact caused material harm to the community. I don't know what precipit=
ated this change, but props to you all for stepping up.<br /><br />Best,<di=
v>Eric</div>
<p></p>
-- <br />
You received this message because you are subscribed to the Google Groups &=
quot;Bitcoin Development Mailing List" group.<br />
To unsubscribe from this group and stop receiving emails from it, send an e=
mail to <a href=3D"mailto:bitcoindev+unsubscribe@googlegroups.com">bitcoind=
ev+unsubscribe@googlegroups.com</a>.<br />
To view this discussion on the web visit <a href=3D"https://groups.google.c=
om/d/msgid/bitcoindev/a9f31b7f-08c9-4ee0-97a0-1c8708ad5c63n%40googlegroups.=
com?utm_medium=3Demail&utm_source=3Dfooter">https://groups.google.com/d/msg=
id/bitcoindev/a9f31b7f-08c9-4ee0-97a0-1c8708ad5c63n%40googlegroups.com</a>.=
<br />
------=_Part_257618_1264436344.1720053887747--
------=_Part_257617_667154445.1720053887747--
|