Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

Already on GitHub? Sign in to your account

RFC: move <0.10.3 and <0.11.1 to 'insecure' directory #1091

Closed
laanwj opened this Issue Oct 15, 2015 · 5 comments

Comments

Projects
None yet
5 participants
Contributor

laanwj commented Oct 15, 2015

The executables for these version should under no conditions be used anymore, they are a liability. May be even better to delete them, but moving them to an explicitly warning path is a good step.

Note: the source tarballs should be retained and stay in the current path.

Contributor

jonasschnelli commented Oct 15, 2015

Agree with @laanwj. Maybe even add (in addition the the insecure path) a INSECURE-bitcoin-0.11.1-osx-signed.dmg (a.s.o.). So people downloading through a link will also notice when looking at the filename itself.

Contributor

harding commented Oct 15, 2015

Moving them to an insecure directory sounds like a good solution to me (although I'm fine with removing them too). I suggest a short README.txt for the insecure directory that says something like:

The releases in this directory contain known security flaws and should not be used. Information about some known flaws can be found at the following links:

If you have any questions, please feel free to ask for help: https://bitcoin.org/en/bitcoin-core/help

Contributor

saivann commented Oct 15, 2015

I think I applied all required changes, please feel free to take a look if you see something wrong (e.g. 0.8.* and 0.9.* had to be moved to insecure/ right, not just the 0.10.* releases?)

On prefixing all files with INSECURE-, not a bad idea, I'll let others, especially Wladimir, comment if they think it's worth it, or if there is any reason not to do this.

Contributor

saivann commented Oct 19, 2015

Closing the issue as I believe it has been addressed, but please leave a comment if you find anything that needs fixing. Thanks!

@saivann saivann closed this Oct 19, 2015

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment