Bitcoin Core developers introduce a "critical bug" disclosure policy aimed at communicating more effectively about Bitcoin security vulnerabilities.
On July 3, Bitcoin Core developer Antoine Poinsot and five others wrote to members of the Bitcoin Development mailing list: "The project has historically had a poor record of publicly disclosing security-critical vulnerabilities, whether reported externally or discovered by contributors."
Antoine Poinsot said there is a dangerous perception that Bitcoin Core is vulnerability-free, but Poinsot emphasized that this is not the case. Poinsot noted that "this perception is dangerous and, unfortunately, inaccurate."
Poinsot said the new policy will allow for better communication about the risks of running older versions of Bitcoin Core and will provide a standardized disclosure process that will give researchers more incentive to discover and disclose vulnerabilities responsibly. "Disclosing security vulnerabilities to a wider group of contributors can help prevent future security vulnerabilities." (Cointelegraph)