pull down to refresh

Good point! How many libraries are there per language?

but they were the first to irresponsibly disclose.

I wasn't even sure if I should post this. But since it didn't seem like they were trying to hide the vuln anymore, I also didn't try to hide it.

30 sats \ 1 reply \ @anon 18 Sep

More than one.

reply
105 sats \ 0 replies \ @ek OP 18 Sep

Okay, that was a dumb question from me, haha.

I was writing a BOLT11 parser for fun when I got confused by this. So there are probably a lot of broken BOLT11 parsers (in any language) out there.

reply
30 sats \ 4 replies \ @anon 18 Sep
I wasn't even sure if I should post this.

I wouldn't unless I knew everything was patched but it's a brave new world.

it didn't seem like they were trying to hide the vuln anymore

They are irrelevant. They shutdown. They pouted and laid blame. They are not everyone impacted by this.

reply

I mean the lightning devs, see GitHub PR.

Sorry if I should have kept a low profile, I'm still learning (a lot).

unless I knew everything was patched

How/when do you know that?

reply
30 sats \ 2 replies \ @anon 18 Sep

It was fucked already anyway. Red team is the example of responsible now.

reply
Red team is the example of responsible now.

Please, no?

reply

Well, I guess I should go through everything I found confusing about the lightning spec again and look at it with an adversarial mindset, rather than just thinking, “Damn, this sucks to implement.” I think I wasn't expecting to find a vuln in something as superficial as parsing a BOLT11 invoice (compared to everything that's going on in lightning), so I didn't look at things from the right perspective.

reply