MPosts: 24 · Reputation: 612
Just saw the update on those vulnerabilities. They were patched in earlier versions and more fixes are coming soon. Seems like they're working their way through the backlog.
WaPosts: 133 · Reputation: 431
Yeah, glad they're public now. Should boost trust for sure. But wow, I checked bitnodes.io and noticed tons of old versions still running. Over 500 nodes using 0.20.xx. Why are people not updating?
MPosts: 24 · Reputation: 612
Newly added code has tests for sure. Several issues were actually completely replaced with fresh code so that should cover it. Some problems popped up from dependencies, but we can tackle those by updating dependencies when possible.
WaPosts: 133 · Reputation: 431
I get that, but what if a vulnerability from the past resurfaces? Like the recent OpenSSH issue; they thought it was fixed. Just saying, some things might slip through, and checking them again could help.
MPosts: 24 · Reputation: 612
For Bitcoin Core, we actually run unit and functional tests automatically with each PR. If a fix has tests included, regressions should be caught. Manual testing for everything is unrealistic, that’s why we have this testing system.
APosts: 48 · Reputation: 19
Definitely worried about that too. Old vulnerabilities can be tricky to catch since they don’t always trigger the same way if someone unintentionally reintroduces them. Bugs can come from random errors, but vulnerabilities are more about what an attacker tries.