Post
Topic
Board Development & Technical Discussion
Merits 1 from 1 user
Re: The duplicate input vulnerability shouldn't be forgotten
by
theymos
on 27/09/2018, 21:50:42 UTC
⭐ Merited by Coding Enthusiast (1)
Maybe the alert system could be modified to only warn the user with a predefined warning to go check the news because something is going on.

I suggested something like that previously.

I do think that some alert system would be good, though the old alert system's propagation method and especially its single-key authentication was really bad, so I don't mourn its loss specifically. A new system could work by polling DNS TXT records + signatures (eg. alert.bitcoincore.org.    TXT    "predefined_alert=2 time=... sig=ABCD+/012..."), with many domains+keys controlled by many people and perhaps a requirement that at least a few of them agree before displaying an alert.