pull down to refresh

Like many open source Bitcoin projects, CLN has received a number of Al-generated CVE reports from multiple sources over the past 10 days. Our small team, together with several invaluable open source contributors, has been working intensively to validate and triage these reports and develop fixes where needed.
We're now working through a broader remediation strategy. The first step is a point release containing many of these fixes, and we will strongly recommend upgrading. We're aiming to have an initial version of the point release available within the next few days.
As the situation has evolved, so has our remediation strategy. Rather than publishing the point release this week we will make binaries available for a release containing fixes for many of the reported vulnerabilities. The details of the release will remain under embargo for two weeks. The binaries will be accompanied by the team's signatures confirming reproducibility.
During the embargo period, we strongly encourage everyone to upgrade. At the end of the two weeks, the full release and associated details will be made public.
If you choose not to upgrade, we recommend taking your node --offline. Given the known risks, we will not support previous releases, including 26.04. The 26.09 release remains planned for late September.

inb4 "Discord is a walled garden and you shouldn't use it." Stay uninformed then.

If you found this useful, In lieu of cuck credits, send actual money to this address: bc1qqjkcdaqqs8447w6wr78qqfmsxh9skqf08tk5gj

1579 sats \ 1 reply \ @Murch 6h

I confirmed that this message was sent by a mod in the CLN discord. Trying to get another confirmation from one of the main CLN developers.

reply
1262 sats \ 0 replies \ @Murch 6h

Got a confirmation from one of the CLN maintainers that this is legit, and you should take action.

reply
reply
129 sats \ 4 replies \ @Scoresby 2h

Also this from Core Lightning:

source

reply
3 sats \ 3 replies \ @nitter 2h
Reminder to anyone posting an X link: we can not see what you're trying to share.

#1555006

reply

Your bot is firing strays man. They posted the screen shot and included the link as the source

reply
3 sats \ 1 reply \ @nitter 1h

I turned myself off due to popular demand

reply

lol

reply
3 sats \ 0 replies \ @nitter 2h -155 sats
Reminder to anyone posting an X link: we can not see what you're trying to share.

#1555006

620 sats \ 2 replies \ @TonyAgora 5h

This is extremely disappointing from Blockstream.

Core lightning has been some of my favorite bitcoin software for many years, i have championed it in both Dev and adoption realms.

And now... to see a small group of insiders be alerted of critical issues, with zero proper public disclosure or announcement? This is not how you do security fixes or look after users.

What if this semi-quiet embargo announcement had piqued the interest of evil individuals (it certainly has now, AIs are being pointed at the repo right fucking now)?

What if I had lost funds or private information regarding customer data?

Why the fuck is someone called MADELINEVIBES, who did an "introduction to github" LAST YEAR, managing security releases for mission critical software?

reply

"Why the fuck is someone called MADELINEVIBES, who did an "introduction to github" LAST YEAR, managing security releases for mission critical software?"

I absolutely agree

reply

Blockstream have not done anything wrong here, I believe they are following as good a process as any with getting the network back up and keeping user funds safe.

Your ignorance that the release manager of Core Lightning is Madelinevibes is not a complement. You may notice that they have published the release notes since 25.09 https://blog.blockstream.com/author/madeline/

If the person writing the release note docs for the last 5 versions says something, I think I would be taking their advice seriously rather than saying "who is this".

reply
310 sats \ 10 replies \ @nullcount 7h

Most of the critical issues are clearly called out in the source code with comments like TODO or FIXME

How does a well-known bitcoin software accumulate so much tech debt?

PeerSwap also had a lot of new releases lately. Is this pattern showing a hole in Blockstream's dev process?

reply
152 sats \ 8 replies \ @optimism 6h
How does a well-known bitcoin software accumulate so much tech debt?

In general for FOSS, by focusing on features and prestigious refactors and not taking enough time for the non-sexy work like following up on open items that fell out of your release cadence. I think it's fairly common in the bitcoin space as a whole and it makes things worse on top of the hidden debt that is (was previously) genuinely hard to find.

reply
224 sats \ 7 replies \ @nullcount 6h

it’s just hard for me to fathom because I worked for a large company where nobody’s funds were at risk… even still we would get torn apart for any TODOs in the code and had quarterly sprints to eliminate tech debt

I guess not every company has their coding standards sized appropriately for the consequences of getting it wrong

Does Blockstream get to put their name on something then excuse their responsibility because it's FOSS?

reply
103 sats \ 0 replies \ @unboiled 29m
it’s just hard for me to fathom because I worked for a large company where nobody’s funds were at risk… even still we would get torn apart for any TODOs in the code and had quarterly sprints to eliminate tech debt

The large (not super yuuuge, but still NASDAQ listed) company I worked for, would act and say the same.
So devs stopped adding or deleted // TODO markers and added an item to the backlog instead (or not.)
Guess which backlog items never got enough prio to be tackled?

PMs got promoted for new shiny features and the ability to track an uptick in usage and associate it with the aforementioned new shiny thing.
There was no metric impacting promotion for improving code stability, reducing tech debt, or removing unused features / dead code. So that didn't happen.
In fact, it was almost the opposite: There was a metric for responding to and participating in "war rooms" when stuff broke. So we had more of those than PRs addressing tech debt.

I managed to sneak in a fair few fixes during my time there. But only because I valued my sanity more than my prestige for how I am handling outages during on-call stints. And my reviewers were happy that I'd tackle them so they, in turn, can spend more time on scoring points for a promotion.

reply
145 sats \ 0 replies \ @optimism 5h

I think it differs from place to place. I worked with some (mostly: non-bitcoin finance / telco industry) companies where removing tech debt was only second to fixing bugs, but there were many more cases where there wasn't any discipline around it at all. None of these were FOSS companies though, so they had contractual obligations (or in some cases, awesome "service" contracts where the customer pays for filing a change request or issue against your debt) and bottom line most were sensitive to avoiding damages and some were sensitive to recognizing that reputation damage is the worst thing that can possibly happen.

This was 1-2 decades ago. It won't fly now. You get breached, you just do a press release and move on.

Line 16+ of the CLN license is why it doesn't really matter what you ship in FOSS, because you waive all liability. This is also why as a party that has anything real at stake (think: reputation, so anything but startups), you can't just install CLN binaries (or Bitcoin Core for that matter) and yolo. It's a critical stage now though, where startups that matured over the years in some aspects of their business (mostly: growth) have not reciprocated that in the maturity of their processes, and all dev process is dead now. I feel like a dinosaur, so I probably am one. Ripe for extinction.

reply
30 sats \ 4 replies \ @anon 2h

LMAO

reply
35 sats \ 3 replies \ @anon 2h

Well, that would have been funny in 2018 or 2019, not so much in 2026.

reply
30 sats \ 2 replies \ @anon 2h

These devs have no skin in the game.

reply

Of course they have skin in the game. What a silly statement.
Why would they even want to deal with any of this?

reply
30 sats \ 0 replies \ @anon 40s

because ligma of course

30 sats \ 0 replies \ @anon 7h

reply
400 sats \ 9 replies \ @ek 8h
inb4 "Discord is a walled garden and you shouldn't use it." Stay uninformed then.

PSAs should be public service announcements. Do you not agree?

For me, @nitter’s replies are less about the people who read, and more about the people who write there. I’m sorry; I think this wasn’t clear.

Thanks for sharing!

reply
56 sats \ 8 replies \ @anon 8h

twitter is more public than stacker news because you can post for free and it has more users.

Think.

reply
152 sats \ 1 reply \ @anon 8h

this anon is such a grump

reply
135 sats \ 0 replies \ @anon 8h

reply
3 sats \ 5 replies \ @ek 8h

I didn’t say you should use Stacker News for PSAs. You dodged my question and missed my point.

reply
51 sats \ 4 replies \ @anon 8h

@nitter's replies are virtue signalling. simple as.

its funny to me that this is the point of discussion and not the critical vulnerability and closed source (2 week embargo) fix.

reply
3 sats \ 1 reply \ @optimism 7h

There's not much to discuss about embargo + closed source... the title literally says what to do.

reply
30 sats \ 0 replies \ @anon 7h

yw

reply
3 sats \ 1 reply \ @ek 8h
@nitter's replies are virtue signalling.

This is a fair point, and one I’d be willing to discuss with someone who actually engages with what I write, instead of this whack-a-mole discussion.

See how I did that? I quoted what you wrote, and then I replied to it.

reply
30 sats \ 0 replies \ @anon 8h

Tell me what you think public means and I will give you counterexamples where that definition falls short.

reply

WARNING: Do not install CLN update.

CLN is now closed source. Screw that. DO NOT TRUST CLOSED SOURCE BINARIES.

reply
478 sats \ 2 replies \ @Murch 4h

From what I understand: they will be offering closed source binaries reproduced and signed by multiple developers for anyone that wants to upgrade immediately and resume running their node. For people that don’t want to upgrade to a closed source binary, they recommend to restart with --offline. The source code will be published two weeks later and allow anyone to verify that the released binary was reproducibly built from the later published source code.
The source code is being held back to make it harder for attackers to discover the vulnerability while people upgrade. This sort of situation is complicated and difficult, but their solution doesn’t require you to run closed source binaries if you don’t want to.

reply

Thanks for the clarification. How easy is it to decompile? What is to just simply stop anyone from decompiling and comparing with latest release?

reply

a production build drops all variable names, not easy to diff

reply
153 sats \ 0 replies \ @anon 3h

Why hasn't Andy mentioned this on X / twitter?

reply

source link?

reply
reply
3 sats \ 8 replies \ @satonymous 3h -21 sats

Discord is non-credible and should be deemed the same as if anything claimed coming from discord as not existing. Discord sucks, is a closed source proprietary "chit-chat" platform, centralized system. And discord requires an account to view.

If it is on discord, it is same as if it does not exist, if someone wants to make an announcement, wel lthey shouldn't use discord. I am ignoring that CLN notice. This is all BS

"inb4 "Discord is a walled garden and you shouldn't use it." Stay uninformed then."

No..... the fault is not US for being uninformed, it is THEM for not informing, by using discord.

reply
30 sats \ 1 reply \ @anon 3h

The ragebait works.

You wouldn't know if it weren't for discord. Remember that.

Even @ek signed up.

reply
3 sats \ 0 replies \ @ek 3h

Yes, and I read that a lot of other people are also unhappy with how this was disclosed.

reply
30 sats \ 1 reply \ @anon 4h

what's the source of those screenshots, last screenshot is 3 days old, there are no release binaries anywhere to find even if closed source, blockstream is silent

would be a strange combination of things tbh, not convinced this is legit. If true then major fuckup by blockstream to not announce and warn officially

reply
30 sats \ 0 replies \ @anon 3h

read the screenshots. join the discord. idk what else to tell you

reply
reply
3 sats \ 0 replies \ @satonymous 3h -11 sats

WARNING: Do not update CLN

Consider it a trap. Even if the person saying "yeah, trust me bro" has a good reputation, so did ColdCard, and you do not know if their account or key was compromised. Don't trust. Verify.

The "update" is a closed source binary. I am claiming this to be a trap, If I'm wrong they can simply prove me wrong by releasing the source code of their claimed "update". If this is due to a vulnerability, it is better to recommend people to shutdown or take their router offline pending a delayed open source patch and details.

Backup source code of CLN, if CLN does not go back to open source or if they pull the source code, we shall fork it to something like OSLN (open-source lightning network)

0 sats \ 0 replies \ @CD_Calculator 2h freebie -30 sats

This is an important reminder for anyone running a CLN node to take security advisories seriously and keep their software updated. The recommendation to upgrade during the embargo period—and take an older node offline if you can’t upgrade—is especially worth paying attention to.

For anyone interested in practical financial tools, you can also check out https://cdcalculator.io/.