bitcoin-dev

A "Free" Relay Attack Taking Advantage of The Lack of Full-RBF In Core

A "Free" Relay Attack Taking Advantage of The Lack of Full-RBF In Core

Original Postby Antoine Riard

Posted on: July 21, 2024 02:06 UTC

The email from Antoine to Ava Chow on the Bitcoin Development Mailing List highlights a concern regarding the processes and ethical considerations within the community, specifically around the removal of individuals from the security list.

Antoine questions the decision not to allow an individual, referred to as Peter, the opportunity to defend his position or contribute to the discussion about his own removal from this list. He argues that such actions seem counterintuitive to the project's aspirations towards decentralization and a technical meritocracy. Antoine believes excluding someone without a consensus or in absence of an operational security emergency is both naive and short-sighted.

Antoine explains that categorizing the Bitcoin Core project list to exclude certain members can lead to oversights, particularly when it concerns security issues that may arise from less familiar parts of the codebase or from external factors like networking stack changes or protocol implications. He points out that experience with older code segments and novel challenges should be valued, citing Peter's qualifications that exceed these requirements.

He further critiques the criteria used by the security list members to determine what constitutes an 'active' contributor, suggesting that contributions are not solely measured by current activity but also by the depth and relevance of one's work. Antoine shares his own shift in focus from lightning development to core aspects due to emerging issues requiring attention at the base-layer, arguing that such shifts do not diminish one’s capacity to contribute effectively. He emphasizes the importance of having experienced individuals during critical times, such as addressing severe bugs or forks, underscoring the value of shared cultural and ethical standards among contributors.

Lastly, Antoine mentions his intention to propose Peter's readmission to the security mailing list through the bitcoin-meta repository after the current discussion cools down, expressing his trust in Peter's competence and experience over others currently on the list. He concludes by acknowledging Ava's role in the matter and ensuring her continued involvement in future security discussions related to Bitcoin Core.