pull down to refresh

After 5 years? Yeah. After 2 months? Nearly nothing. Before release? None at all.

126 sats \ 3 replies \ @OT 2 Aug

People still set up wallets with low entropy. As soon as its public, thieves would go looking for the exploit and find it fast.

reply

I'm not sure what you mean. The key to finding bugs is finding them early.

The earlier you find them, the less damage they do, or maybe the real truth is the inverse: the longer you don't find them, the more damage they do.

reply
126 sats \ 1 reply \ @OT 2 Aug

In this particular situation users have already set up a flawed wallet. Coinkite can fix the vulnerability but as soon as they disclose to the pubic it wouldn't take long for an attacker to find the exploit and steal the slow mover coins.

reply

Yes. So there is no great answer on a bug that has accumulated vulnerable coin for 5+ years. I cannot see any way to do it right when that history already built up like that. That is probably the other thing, besides the speed at which this went from question mark to "found it", in which this is unprecedented - I honestly don't remember any fundamental flaw with such exposure time in our space. Do you?

reply