Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

security issues in Gridcoin #34

Open
Erkan-Yilmaz opened this issue Aug 16, 2017 · 9 comments
Open

security issues in Gridcoin #34

Erkan-Yilmaz opened this issue Aug 16, 2017 · 9 comments
Labels

Comments

@Erkan-Yilmaz
Copy link
Owner

Erkan-Yilmaz commented Aug 16, 2017

See here for upcoming changes due to exploits.


August 18 (via cm):

  • ability to exfiltrate user's email addresses (used also in BOINC) from the Gridcoin blockchain
  • hijacking beacons (stealing an user's CPID registration)

cm3


Martin Grothe:

martin16


Gridcoin devs:

  • August 16: ravon: "the first vulnerability was fixed in 3.5.9.4 (July 16) while the second one was scheduled for NN2.0 or right before it" (chat)
  • August 16: reply by Rob
  • August 16: "There are actually two articles. The issues in the old one have been fixed by the author (Martin) while the issues in the new one remain. We're working with input from the author to see how this can be solved." (link)
  • August 15: about old article: "And it is outdated. The mechanisms described are no longer used. The attacks wont work. Of course, the new mechanisms have equal amount of holes." (chat)


See also my comments:

  • August 15: "Thx, Martin! I'll share with others. From what I see u looked at Gridcoin 3.5.9.8 version (17 days old) + it seems u got no replies by dev"
  • August 15: "You are aware that Martin posted his findings - in public - on his blog on August 13 (let me look, I have now Aug.16 here),

    they talked about it on a security conference + it is tweeted by 'em all over on twitter with hashtag Gridcoin..."


The downvote faction on steemit has again shown what they are capable of (A)...


Thus... please find a copy

  • HERE (version: August 15)
    • after posting in the forum, the article on steemit got downvoted massively, see here

(A) see problems with steemit




voices in the community:





@Erkan-Yilmaz Erkan-Yilmaz changed the title under investigation: some tweets popped up about security issues in Gridcoin under investigation: security issues in Gridcoin Aug 17, 2017
@Erkan-Yilmaz
Copy link
Owner Author

Erkan-Yilmaz commented Aug 19, 2017

upcoming changes:


the new Gridcoin PoS kernel v8:

  • "The most notable effect is that magnitude does no longer affect your stake weight. Investors and BOINCers now have the same chances to mint a block. This drastic change was needed to eliminate an exploit. On the other hand a compensation for less rich BOINCers is already being designed."

@Erkan-Yilmaz
Copy link
Owner Author

version 3.6.0.1 has been released 3 days ago which has the new Gridcoin PoS kernel v8 which will be in effect then at block 1010000 (est. 6-7 days)

@Erkan-Yilmaz
Copy link
Owner Author

new mandatory released 5 days ago:

also see:

@Erkan-Yilmaz
Copy link
Owner Author

see also:

excerpts/selection of weaknesses:

@Erkan-Yilmaz
Copy link
Owner Author

@Erkan-Yilmaz
Copy link
Owner Author

Erkan-Yilmaz commented Sep 21, 2017

@Erkan-Yilmaz Erkan-Yilmaz changed the title under investigation: security issues in Gridcoin security issues in Gridcoin Sep 21, 2017
@Erkan-Yilmaz
Copy link
Owner Author

Erkan-Yilmaz commented Sep 28, 2017

to GRCpool users:

@Erkan-Yilmaz
Copy link
Owner Author

@tomasbrod
Copy link

In case you are wondering what #private info can be recovered, it was already published:

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

No branches or pull requests

3 participants
@Erkan-Yilmaz @tomasbrod and others