Bitcoin Core Vulnerability Disclosures Need for Ongoing Testing?

5 replies 421 views
matrix2021Full Member
Posts: 24 · Reputation: 612
#1Jul 4, 2019, 02:07 PM
Just saw the update on those vulnerabilities. They were patched in earlier versions and more fixes are coming soon. Seems like they're working their way through the backlog.
5 Reply Quote Share
wallet_vaultFull Member
Posts: 133 · Reputation: 431
#2Jul 4, 2019, 08:20 PM
Yeah, glad they're public now. Should boost trust for sure. But wow, I checked bitnodes.io and noticed tons of old versions still running. Over 500 nodes using 0.20.xx. Why are people not updating?
4 Reply Quote Share
matrix2021Full Member
Posts: 24 · Reputation: 612
#3Jul 5, 2019, 05:04 PM
Newly added code has tests for sure. Several issues were actually completely replaced with fresh code so that should cover it. Some problems popped up from dependencies, but we can tackle those by updating dependencies when possible.
2 Reply Quote Share
wallet_vaultFull Member
Posts: 133 · Reputation: 431
#4Jul 5, 2019, 08:23 PM
I get that, but what if a vulnerability from the past resurfaces? Like the recent OpenSSH issue; they thought it was fixed. Just saying, some things might slip through, and checking them again could help.
5 Reply Quote Share
matrix2021Full Member
Posts: 24 · Reputation: 612
#5Jul 5, 2019, 08:58 PM
For Bitcoin Core, we actually run unit and functional tests automatically with each PR. If a fix has tests included, regressions should be caught. Manual testing for everything is unrealistic, that’s why we have this testing system.
2 Reply Quote Share
Posts: 48 · Reputation: 19
#6Jul 5, 2019, 09:42 PM
Definitely worried about that too. Old vulnerabilities can be tricky to catch since they don’t always trigger the same way if someone unintentionally reintroduces them. Bugs can come from random errors, but vulnerabilities are more about what an attacker tries.
1 Reply Quote Share

Related topics