bitcoin-dev

A "Free" Relay Attack Taking Advantage of The Lack of Full-RBF In Core

A "Free" Relay Attack Taking Advantage of The Lack of Full-RBF In Core

Original Postby Antoine Riard

Posted on: July 21, 2024 02:13 UTC

The email from Antoine to Peter touches on several critical issues within the open-source community, particularly concerning the management of sensitive security information in bitcoin's infrastructure.

Antoine expresses skepticism towards the current approach taken by moderators in handling pull requests (PRs), suggesting that these are often closed without proper acknowledgment of reported security issues. This highlights a broader concern about the competence or willingness of community actors to address security vulnerabilities adequately.

Antoine further discusses the reluctance within the community to adapt their bitcoin infrastructure deployment or zero-confirmation acceptance flow, despite the introduction of mempoolfullrbf nearly two years prior. This reluctance is seen as a barrier to strengthening cultural norms in an ecosystem increasingly reliant on codebases outside of bitcoin core for economic transactions.

In an effort to address these concerns, Antoine proposes to re-advocate for Peter's integration into the bitcoin security mailing list by reopening an issue on the GitHub repository, indicating a level of trust in Peter's capabilities and understanding of the issues at hand. The inclusion of a specific GitHub issue (bitcoin-core/meta/issues/5) suggests that there is an ongoing discussion worth pursuing, which could potentially lead to improvements in how security information is managed within the community.

Overall, the email underscores the challenges faced by the open-source community in securing bitcoin's infrastructure and the importance of fostering a culture that prioritizes security and effective communication. Antoine's outreach to Peter not only reflects trust in his expertise but also represents a proactive step towards enhancing the community's approach to security issues.