|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
このプロジェクトはこれまで、外部から報告されたか、貢献者によって発見されたかにかかわらず、セキュリティ クリティカルなバグを公に公開するという点でうまくいっていませんでした。

Bitcoin Core Developers Roll Out New Security Vulnerability Disclosure Policy
ビットコインコア開発者が新しいセキュリティ脆弱性開示ポリシーを発表
A group of Bitcoin core developers have rolled out a new policy to disclose security vulnerabilities on the Bitcoin blockchain.
ビットコインのコア開発者のグループは、ビットコインのブロックチェーン上のセキュリティの脆弱性を公開するための新しいポリシーを展開しました。
“The project has historically done a poor job at publicly disclosing security-critical bugs, whether externally reported or found by contributors,” said developer Antoine Poinsot in an email sent to the Bitcoin developer mailing list.
開発者のアントワーヌ・ポアンソ氏は、ビットコイン開発者メーリングリストに送った電子メールの中で、「このプロジェクトは歴史的に、外部から報告されたか貢献者によって発見されたかにかかわらず、セキュリティクリティカルなバグを公に公開するという点で不十分だった」と述べた。
“This has led to a situation where a lot of users perceive Bitcoin Core as never having bugs. This perception is dangerous and, unfortunately, not accurate.”
「このため、多くのユーザーがビットコインコアにはバグがないと認識している状況が生じています。この認識は危険であり、残念ながら正確ではありません。」
The new disclosure policy would classify disclosed vulnerabilities into one of four categories based on severity: low, medium, high and critical.
新しい開示ポリシーでは、開示された脆弱性は、重大度に基づいて低、中、高、重大の 4 つのカテゴリのいずれかに分類されます。
Low severity bugs would be disclosed within two weeks after a fixed version is released, while medium and high severity bugs would be disclosed two weeks after the last affected software release reaches its end of life.
重大度の低いバグは、修正バージョンがリリースされてから 2 週間以内に公開されますが、重大度が中および高のバグは、影響を受ける最後のソフトウェア リリースがサポート終了に達してから 2 週間後に公開されます。
Critical bugs, on the other hand, would not be considered in the standard policy and would require an ad-hoc procedure regarding its disclosure. The developers would consider any bug that threatens the entire network’s integrity to fall in this bracket.
一方、重大なバグは標準ポリシーでは考慮されず、その開示に関してアドホックな手順が必要になります。開発者は、ネットワーク全体の整合性を脅かすあらゆるバグがこの枠に当てはまると考えます。
The new policy is expected to be gradually rolled out in the coming months, but in the spirit of following through with the promise of appropriate disclosures, a page has been added to the official Bitcoin core website summarizing the vulnerabilities that impacted the network.
新しいポリシーは今後数カ月以内に段階的に展開される予定だが、適切な開示の約束を貫く精神で、ビットコインコアの公式ウェブサイトにネットワークに影響を与えた脆弱性をまとめたページが追加された。
The document details 12 disclosures that impacted the Bitcoin network before the version 0.21.0 of its software was released.
この文書では、ソフトウェアのバージョン 0.21.0 がリリースされる前にビットコイン ネットワークに影響を与えた 12 件の開示について詳しく説明しています。
One of these bugs was a malicious BIP-72 Uniform Resource Identifier (URI), which is used to facilitate payments and interact with wallet addresses, that could cause the BIP-70 implementation in Bitcoin core to silently crash.
これらのバグの 1 つは、支払いを容易にし、ウォレット アドレスとやり取りするために使用される悪意のある BIP-72 URI (Uniform Resource Identifier) で、ビットコイン コアの BIP-70 実装がサイレント クラッシュを引き起こす可能性があります。
Other disclosures included an integer overflow bug that could have caused a network split, a node that could be stalled for hours, and a denial of service (DoS) vulnerability that affected older versions of Bitcoin core.
その他の開示には、ネットワーク分割を引き起こす可能性のある整数オーバーフローのバグ、数時間停止する可能性のあるノード、古いバージョンのビットコインコアに影響を与えるサービス拒否 (DoS) の脆弱性などが含まれています。
“I have to say this is one of the most compelling statements I’ve seen from the bitcoin/Bitcoin Core team in over 10 years,” said Bitcoin developer Eric Voskuil.
ビットコイン開発者のエリック・ヴォスクイル氏は、「これは私が10年以上にわたってビットコイン/ビットコインコアチームから見た中で最も説得力のある声明の1つであると言わざるを得ません」と述べた。
“Many other projects have been on the receiving end of this misperception, and it has in fact caused material harm to the community. I don’t know what precipitated this change, but props to you all for stepping up.”
「他の多くのプロジェクトもこの誤解の影響を受けており、実際にコミュニティに重大な損害を与えています。何がこの変化を引き起こしたのかはわかりませんが、皆さんがステップアップすることを応援します。」
免責事項:info@kdj.com
提供される情報は取引に関するアドバイスではありません。 kdj.com は、この記事で提供される情報に基づいて行われた投資に対して一切の責任を負いません。暗号通貨は変動性が高いため、十分な調査を行った上で慎重に投資することを強くお勧めします。
このウェブサイトで使用されているコンテンツが著作権を侵害していると思われる場合は、直ちに当社 (info@kdj.com) までご連絡ください。速やかに削除させていただきます。

































