Bitcoin has spent 17 years surviving one of the most adversarial environments in software.
But Bitcoin Core isn’t where most users interact with Bitcoin.
They interact through wallets, hardware devices, Lightning implementations, libraries, exchanges, signing infrastructure and other software built around it.
Over the past few months, I’ve been researching the security of projects across this ecosystem, and the uncomfortable part isn’t that vulnerabilities exist.
It’s how little continuous adversarial security research some important projects actually receive.
An audit is a snapshot. Open source doesn’t mean someone capable has actually reviewed the code. A large number of users doesn’t mean the project has been continuously attacked by security researchers.
And then there’s the incentive problem.
If reporting a vulnerability responsibly means hunting down a contact, waiting weeks for a response, receiving no bounty or recognition, and sometimes being treated as an inconvenience, eventually good researchers spend their time somewhere else.
Blackhats don’t need a disclosure policy.
That leaves us with a strange situation:
Bitcoin teaches us “don’t trust, verify,” while much of the software surrounding Bitcoin is trusted far more than it is independently verified.
I ended up writing a fairly detailed piece about what I’ve seen and why I think this is becoming a real problem.
I’m not linking it here because I’d rather this not turn into self-promotion.
But I’d genuinely like to know whether people working deeper in Bitcoin have noticed the same thing.
[link] [comments]
You can get bonuses upto $100 FREE BONUS when you:
💰 Install these recommended apps:
💲 SocialGood - 100% Crypto Back on Everyday Shopping
💲 xPortal - The DeFi For The Next Billion
💲 CryptoTab Browser - Lightweight, fast, and ready to mine!
💰 Register on these recommended exchanges:
🟡 Binance🟡 Bitfinex🟡 Bitmart🟡 Bittrex🟡 Bitget
🟡 CoinEx🟡 Crypto.com🟡 Gate.io🟡 Huobi🟡 Kucoin.
Comments