Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

True, though I would hope most services don't have public facing bitcoind instances to begin with...


Ideally, no, but with SSL, and a very-strong password, it might not be worse than other options for automating payouts... until a major bug like this comes along.

For comparison, the Bitcoin RPC password timing bug - https://github.com/bitcoin/bitcoin/issues/2838 - would have been a more slower and blatant/detectable way to compromise the same sorts of bitcoin RPC daemons.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: