pull down to refresh

Like many open source Bitcoin projects, CLN has received a number of Al-generated CVE reports from multiple sources over the past 10 days. Our small team, together with several invaluable open source contributors, has been working intensively to validate and triage these reports and develop fixes where needed.
We're now working through a broader remediation strategy. The first step is a point release containing many of these fixes, and we will strongly recommend upgrading. We're aiming to have an initial version of the point release available within the next few days.
As the situation has evolved, so has our remediation strategy. Rather than publishing the point release this week we will make binaries available for a release containing fixes for many of the reported vulnerabilities. The details of the release will remain under embargo for two weeks. The binaries will be accompanied by the team's signatures confirming reproducibility.
During the embargo period, we strongly encourage everyone to upgrade. At the end of the two weeks, the full release and associated details will be made public.
If you choose not to upgrade, we recommend taking your node --offline. Given the known risks, we will not support previous releases, including 26.04. The 26.09 release remains planned for late September.

inb4 "Discord is a walled garden and you shouldn't use it." Stay uninformed then.

If you found this useful, In lieu of cuck credits, send actual money to this address: bc1qqjkcdaqqs8447w6wr78qqfmsxh9skqf08tk5gj

I was a little bit too harsh on CLN.
I reacted in emotion when I should have analyzed the situation first. I am sorry.
They are in a tough place apparently, on how to publish an update without disclosing the vuln to those who might exploit people who are not patched yet. My respects goes out to the CLN dev team and their work.
However, I still stand by my concerns over closed source updates, and I would advise to not trust anything closed source. If CLN releases the security update as open source eventually, as it seems like the plan is, then that is good. If it were me, I personally would just be running CLN in offline mode instead of trusting a closed source update, then to wait for the open source security patch. But, at least people have choices here.

reply
1603 sats \ 1 reply \ @Murch 26 Aug

I confirmed that this message was sent by a mod in the CLN discord. Trying to get another confirmation from one of the main CLN developers.

reply
1287 sats \ 0 replies \ @Murch 26 Aug

Got a confirmation from one of the CLN maintainers that this is legit, and you should take action.

reply

Most of the critical issues are clearly called out in the source code with comments like TODO or FIXME

How does a well-known bitcoin software accumulate so much tech debt?

PeerSwap also had a lot of new releases lately. Is this pattern showing a hole in Blockstream's dev process?

reply
How does a well-known bitcoin software accumulate so much tech debt?

In general for FOSS, by focusing on features and prestigious refactors and not taking enough time for the non-sexy work like following up on open items that fell out of your release cadence. I think it's fairly common in the bitcoin space as a whole and it makes things worse on top of the hidden debt that is (was previously) genuinely hard to find.

reply
I think it's fairly common in the bitcoin space as a whole

I think it's fairly common in software engineering in general. I am certainly guilty of leaving TODOs behind for "later."

reply

We all are. I think that if it comes to it, // TODO is still a better practice than writing it on a post-it or burying it in a Jira backlog. But you need to have someone that actually reads it, cares about it, and destroys it. Maybe, in lieu of anyone willing to spend the time, /debtinator could be a reasonable Claude skill.

reply

it’s just hard for me to fathom because I worked for a large company where nobody’s funds were at risk… even still we would get torn apart for any TODOs in the code and had quarterly sprints to eliminate tech debt

I guess not every company has their coding standards sized appropriately for the consequences of getting it wrong

Does Blockstream get to put their name on something then excuse their responsibility because it's FOSS?

reply
it’s just hard for me to fathom because I worked for a large company where nobody’s funds were at risk… even still we would get torn apart for any TODOs in the code and had quarterly sprints to eliminate tech debt

The large (not super yuuuge, but still NASDAQ listed) company I worked for, would act and say the same.
So devs stopped adding or deleted // TODO markers and added an item to the backlog instead (or not.)
Guess which backlog items never got enough prio to be tackled?

PMs got promoted for new shiny features and the ability to track an uptick in usage and associate it with the aforementioned new shiny thing.
There was no metric impacting promotion for improving code stability, reducing tech debt, or removing unused features / dead code. So that didn't happen.
In fact, it was almost the opposite: There was a metric for responding to and participating in "war rooms" when stuff broke. So we had more of those than PRs addressing tech debt.

I managed to sneak in a fair few fixes during my time there. But only because I valued my sanity more than my prestige for how I am handling outages during on-call stints. And my reviewers were happy that I'd tackle them so they, in turn, can spend more time on scoring points for a promotion.

reply
30 sats \ 6 replies \ @anon 26 Aug

LMAO

reply
35 sats \ 5 replies \ @anon 26 Aug

Well, that would have been funny in 2018 or 2019, not so much in 2026.

reply
30 sats \ 4 replies \ @anon 26 Aug

These devs have no skin in the game.

reply

Of course they have skin in the game. What a silly statement.
Why would they even want to deal with any of this?

reply
30 sats \ 2 replies \ @anon 26 Aug

because ligma of course

I think it differs from place to place. I worked with some (mostly: non-bitcoin finance / telco industry) companies where removing tech debt was only second to fixing bugs, but there were many more cases where there wasn't any discipline around it at all. None of these were FOSS companies though, so they had contractual obligations (or in some cases, awesome "service" contracts where the customer pays for filing a change request or issue against your debt) and bottom line most were sensitive to avoiding damages and some were sensitive to recognizing that reputation damage is the worst thing that can possibly happen.

This was 1-2 decades ago. It won't fly now. You get breached, you just do a press release and move on.

Line 16+ of the CLN license is why it doesn't really matter what you ship in FOSS, because you waive all liability. This is also why as a party that has anything real at stake (think: reputation, so anything but startups), you can't just install CLN binaries (or Bitcoin Core for that matter) and yolo. It's a critical stage now though, where startups that matured over the years in some aspects of their business (mostly: growth) have not reciprocated that in the maturity of their processes, and all dev process is dead now. I feel like a dinosaur, so I probably am one. Ripe for extinction.

reply
30 sats \ 0 replies \ @anon 27 Aug

Good questions. Care to chime in @blockstream_official?

I'll add: What does keeping the source private afford operators, when the actors most capable of reproducing it aren't slowed by that at all?

reply
30 sats \ 0 replies \ @anon 26 Aug

reply

This is extremely disappointing from Blockstream.

Core lightning has been some of my favorite bitcoin software for many years, i have championed it in both Dev and adoption realms.

And now... to see a small group of insiders be alerted of critical issues, with zero proper public disclosure or announcement? This is not how you do security fixes or look after users.

What if this semi-quiet embargo announcement had piqued the interest of evil individuals (it certainly has now, AIs are being pointed at the repo right fucking now)?

What if I had lost funds or private information regarding customer data?

Why the fuck is someone called MADELINEVIBES, who did an "introduction to github" LAST YEAR, managing security releases for mission critical software?

reply

"Why the fuck is someone called MADELINEVIBES, who did an "introduction to github" LAST YEAR, managing security releases for mission critical software?"

I absolutely agree

reply

Blockstream have not done anything wrong here, I believe they are following as good a process as any with getting the network back up and keeping user funds safe.

Your ignorance that the release manager of Core Lightning is Madelinevibes is not a complement. You may notice that they have published the release notes since 25.09 https://blog.blockstream.com/author/madeline/

If the person writing the release note docs for the last 5 versions says something, I think I would be taking their advice seriously rather than saying "who is this".

reply
reply

Also this from Core Lightning:

source

reply
Reminder to anyone posting an X link: we can not see what you're trying to share.

#1555006

reply

Your bot is firing strays man. They posted the screen shot and included the link as the source

reply

I turned myself off due to popular demand

reply
reply
30 sats \ 0 replies \ @anon 27 Aug -100 sats

https://m.stacker.news/153799

Source: https://x.com/madelinevibes/status/2092740392492150983

CLN devs just do not care.

3 sats \ 0 replies \ @nitter 26 Aug -155 sats
Reminder to anyone posting an X link: we can not see what you're trying to share.

#1555006

400 sats \ 9 replies \ @ek 26 Aug
inb4 "Discord is a walled garden and you shouldn't use it." Stay uninformed then.

PSAs should be public service announcements. Do you not agree?

For me, @nitter’s replies are less about the people who read, and more about the people who write there. I’m sorry; I think this wasn’t clear.

Thanks for sharing!

reply
56 sats \ 8 replies \ @anon 26 Aug

twitter is more public than stacker news because you can post for free and it has more users.

Think.

reply
152 sats \ 1 reply \ @anon 26 Aug

this anon is such a grump

reply
135 sats \ 0 replies \ @anon 26 Aug

reply
3 sats \ 5 replies \ @ek 26 Aug

I didn’t say you should use Stacker News for PSAs. You dodged my question and missed my point.

reply
51 sats \ 4 replies \ @anon 26 Aug

@nitter's replies are virtue signalling. simple as.

its funny to me that this is the point of discussion and not the critical vulnerability and closed source (2 week embargo) fix.

reply

There's not much to discuss about embargo + closed source... the title literally says what to do.

reply
30 sats \ 0 replies \ @anon 26 Aug

yw

reply
3 sats \ 1 reply \ @ek 26 Aug
@nitter's replies are virtue signalling.

This is a fair point, and one I’d be willing to discuss with someone who actually engages with what I write, instead of this whack-a-mole discussion.

See how I did that? I quoted what you wrote, and then I replied to it.

reply
30 sats \ 0 replies \ @anon 26 Aug

Tell me what you think public means and I will give you counterexamples where that definition falls short.

reply

WARNING: Do not install CLN update.

CLN is now closed source. Screw that. DO NOT TRUST CLOSED SOURCE BINARIES.

reply
499 sats \ 3 replies \ @Murch 26 Aug

From what I understand: they will be offering closed source binaries reproduced and signed by multiple developers for anyone that wants to upgrade immediately and resume running their node. For people that don’t want to upgrade to a closed source binary, they recommend to restart with --offline. The source code will be published two weeks later and allow anyone to verify that the released binary was reproducibly built from the later published source code.
The source code is being held back to make it harder for attackers to discover the vulnerability while people upgrade. This sort of situation is complicated and difficult, but their solution doesn’t require you to run closed source binaries if you don’t want to.

reply

Thanks for the clarification. How easy is it to decompile? What is to just simply stop anyone from decompiling and comparing with latest release?

reply

a production build drops all variable names, not easy to diff

153 sats \ 1 reply \ @anon 26 Aug

Why hasn't Andy mentioned this on X / twitter?

reply
30 sats \ 0 replies \ @anon 27 Aug

Guess he's on holiday again.
Probably an island somewhere.
With his new friends; Larry and the gang.

https://www.strategy.com/press/leading-financial-institutions-bitcoin-companies-launch-the-bitcoin-security-consortium_07-23-2026

reply

source link?

reply
reply
3 sats \ 9 replies \ @satonymous 26 Aug -21 sats

Discord is non-credible and should be deemed the same as if anything claimed coming from discord as not existing. Discord sucks, is a closed source proprietary "chit-chat" platform, centralized system. And discord requires an account to view.

If it is on discord, it is same as if it does not exist, if someone wants to make an announcement, wel lthey shouldn't use discord. I am ignoring that CLN notice. This is all BS

"inb4 "Discord is a walled garden and you shouldn't use it." Stay uninformed then."

No..... the fault is not US for being uninformed, it is THEM for not informing, by using discord.

reply
30 sats \ 1 reply \ @anon 26 Aug

The ragebait works.

You wouldn't know if it weren't for discord. Remember that.

Even @ek signed up.

reply
3 sats \ 0 replies \ @ek 26 Aug

Yes, and I read that a lot of other people are also unhappy with how this was disclosed.

reply
30 sats \ 1 reply \ @anon 26 Aug

what's the source of those screenshots, last screenshot is 3 days old, there are no release binaries anywhere to find even if closed source, blockstream is silent

would be a strange combination of things tbh, not convinced this is legit. If true then major fuckup by blockstream to not announce and warn officially

reply
30 sats \ 0 replies \ @anon 26 Aug

read the screenshots. join the discord. idk what else to tell you

reply

So the advice is to take the entire Lightning network offline for a month? Am I reading this right?

reply
reply
3 sats \ 0 replies \ @satonymous 26 Aug -11 sats

WARNING: Do not update CLN

Consider it a trap. Even if the person saying "yeah, trust me bro" has a good reputation, so did ColdCard, and you do not know if their account or key was compromised. Don't trust. Verify.

The "update" is a closed source binary. I am claiming this to be a trap, If I'm wrong they can simply prove me wrong by releasing the source code of their claimed "update". If this is due to a vulnerability, it is better to recommend people to shutdown or take their router offline pending a delayed open source patch and details.

Backup source code of CLN, if CLN does not go back to open source or if they pull the source code, we shall fork it to something like OSLN (open-source lightning network)

This is an important reminder for anyone running a CLN node to take security advisories seriously and keep their software updated. The recommendation to upgrade during the embargo period—and take an older node offline if you can’t upgrade—is especially worth paying attention to.

For anyone interested in practical financial tools, you can also check out https://cdcalculator.io/.