|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
비트코인 코어 개발자 팀은 비트코인 내의 보안 취약성에 대한 커뮤니케이션을 개선하기 위해 "중요한 버그" 공개 정책을 도입했습니다.

A team of Bitcoin Core developers has introduced a “critical bug” disclosure policy to improve the communication of security vulnerabilities within Bitcoin.
비트코인 코어 개발자 팀은 비트코인 내의 보안 취약성에 대한 커뮤니케이션을 개선하기 위해 "중요한 버그" 공개 정책을 도입했습니다.
In a message to the Bitcoin Development Mailing List on July 3, developer Antoine Poinsot and five others acknowledged that the project has historically failed in publicly disclosing security-critical bugs, leading users to mistakenly believe that Bitcoin Core is free of issues:
7월 3일 비트코인 개발 메일링 리스트에 보낸 메시지에서 개발자 Antoine Poinsot와 다른 5명은 프로젝트가 역사적으로 보안에 중요한 버그를 공개하는 데 실패하여 사용자가 비트코인 코어에 문제가 없다고 잘못 믿게 만들었다는 점을 인정했습니다.
“The project has historically done a poor job at publicly disclosing security-critical bugs, whether externally reported or found by contributors.”
"이 프로젝트는 역사적으로 외부에 보고되었거나 기여자가 발견한 보안에 중요한 버그를 공개적으로 공개하는 데 있어 부진한 성과를 거두었습니다."
Bitcoin Core is the software that Bitcoin node operators use to access the Bitcoin blockchain, validate transactions, and build blocks, playing a crucial role in securing the over $1.1 trillion locked in the Bitcoin network.
비트코인 코어는 비트코인 노드 운영자가 비트코인 블록체인에 액세스하고, 거래를 검증하고, 블록을 구축하는 데 사용하는 소프트웨어로, 비트코인 네트워크에 잠겨 있는 1조 1천억 달러 이상을 보호하는 데 중요한 역할을 합니다.
The new policy aims to enhance communication about the risks of using outdated versions of Bitcoin Core and to standardise the disclosure process, incentivizing researchers to find and responsibly disclose vulnerabilities. Poinsot believes that making security bugs available to a wider group of contributors can help prevent future issues.
새로운 정책은 오래된 버전의 비트코인 코어 사용에 따른 위험에 대한 의사소통을 강화하고 공개 프로세스를 표준화하여 연구자들이 취약점을 찾아 책임감 있게 공개하도록 장려하는 것을 목표로 합니다. Poinsot는 더 넓은 범위의 기여자 그룹이 보안 버그를 사용할 수 있도록 하면 향후 문제를 예방하는 데 도움이 될 수 있다고 믿습니다.
The policy categorises vulnerabilities into four levels of severity. The first stage, ‘Low’, includes bugs that are hard to exploit and have low impact, such as those requiring access to the victim’s machine.
정책은 취약점을 4가지 심각도 수준으로 분류합니다. 첫 번째 단계인 '낮음'에는 피해자의 컴퓨터에 액세스해야 하는 버그와 같이 악용하기 어렵고 영향이 낮은 버그가 포함됩니다.
The second one is ‘Medium’, which covers bugs with limited impact, such as a local network remote crash.
두 번째는 '중간'으로, 로컬 네트워크 원격 충돌과 같이 영향이 제한적인 버그를 다룹니다.
The last two categories include ‘high’ and ‘critical’, in which there are bugs having significant impact and bugs that threaten the entire network’s integrity, such as manipulating Bitcoin Core to inflate Bitcoin’s supply or committing coin theft, respectively.
마지막 두 가지 범주에는 '높음'과 '위험'이 포함되는데, 여기에는 상당한 영향을 미치는 버그와 비트코인 공급량을 부풀리기 위해 비트코인 코어를 조작하거나 코인 도난을 저지르는 등 전체 네트워크의 무결성을 위협하는 버그가 각각 있습니다.
Low, medium, and high severity bugs will be disclosed two weeks after a fixed version is released, while critical bugs will be disclosed on a case-by-case basis. The policy will be gradually adopted over the coming months.
심각도가 낮음, 중간, 높음 버그는 수정된 버전이 출시된 후 2주 후에 공개되며, 심각한 버그는 사례별로 공개됩니다. 이 정책은 앞으로 몇 달에 걸쳐 점진적으로 채택될 예정입니다.
Poinsot noted that all vulnerabilities fixed in Bitcoin Core versions 0.21.0 and earlier have been disclosed as of July 3, with disclosures for versions 0.22.0 and 0.23.0 to follow later this month and in August. The latest version, Bitcoin Core 27.1, has been adopted.
Poinsot는 비트코인 코어 버전 0.21.0 및 이전 버전에서 수정된 모든 취약점이 7월 3일에 공개되었으며 버전 0.22.0 및 0.23.0에 대한 공개는 이번 달 말과 8월에 이어질 것이라고 언급했습니다. 최신 버전인 Bitcoin Core 27.1이 채택되었습니다.
The new policy was praised by fellow developer Eric Voskuil: “Many other projects have been on the receiving end of this misperception, and it has in fact caused material harm to the community. I don’t know what precipitated this change, but props to you all for stepping up.”
동료 개발자인 Eric Voskuil은 새로운 정책에 대해 다음과 같이 칭찬했습니다. “다른 많은 프로젝트에서도 이러한 잘못된 인식이 받아들여졌고 이는 실제로 커뮤니티에 물질적인 피해를 입혔습니다. 무엇이 이러한 변화를 촉발했는지는 모르겠지만, 여러분 모두의 발걸음을 응원합니다.”
부인 성명:info@kdj.com
제공된 정보는 거래 조언이 아닙니다. kdj.com은 이 기사에 제공된 정보를 기반으로 이루어진 투자에 대해 어떠한 책임도 지지 않습니다. 암호화폐는 변동성이 매우 높으므로 철저한 조사 후 신중하게 투자하는 것이 좋습니다!
본 웹사이트에 사용된 내용이 귀하의 저작권을 침해한다고 판단되는 경우, 즉시 당사(info@kdj.com)로 연락주시면 즉시 삭제하도록 하겠습니다.

































