"there's not much they can do" is a defense.
Responsible disclosure protocol:
1. Report the bug
2. Keep confidential until devs have time to take action for prevention (and in this case, remedial action)
3. Devs reach out to possible victims to update them
4. Confirm that measures in (2 and 3) took place and harm has been minimized
5. Disclose to the public
Clearly Odell did not do steps 3 and 4 that and possibly let people generate insecure wallets for 5 years. You are doing mental gymnastics to defend someone that doesn't deserve it. Stop coping.
Login to reply
Replies (1)
wow - I don't know what else to tell you. It's like you're looking for others to react in exactly the same way you do.
I'm literally trying to figure out what the options were once the bug was known. It's not a defense; it's just recognizing that once that bug is there, it's a pure mess.
And actually your list is the kind of thing I'm looking for to round out my understanding:
1) if you report the bug, then you're giving hackers a heads up, so I don't think you can do this until stacks are safe;
2) there was nothing the devs could have done at that point about the devices that were already out there;
but 3) and 4) - yes, that's the kind of action I was looking for, but as soon as people get a communication from Coinkite on this and word gets out, the hackers get to work, right? I mean - how do you do that and get people to stay quiet until everyone has migrated? That's why I keep bringing up a white hat attack. I can't figure out another way.
I know that the thread started with RHR, but in this sequence I'm not even talking about Odell. I'm really just trying to game out what happens once you realize the bug is out there.