Saturday, 30 November 2019

Friday, 29 November 2019

Bakkt CEO Will Be Asked to Fill Georgia Senate Seat in 2020: Report

Crypto exchange Bakkt’s chief executive Kelly Loeffler has reportedly been picked by Governor Brian Kemp until the special election in November 2020.  Loeffler will likely be asked next week to serve as the replacement of U.S. Senator Johnny Isakson, who has announced plans to vacate his senate seat on December 31, according to a report […]

from CoinDesk https://ift.tt/2L8EPKx

Thursday, 28 November 2019

Wednesday, 27 November 2019

Tuesday, 26 November 2019

Monday, 25 November 2019

Sunday, 24 November 2019

Bitcoin Core 0.19.0 Released

Bitcoin Core version 0.19.0 is now available for download containing multiple improvements and bug fixes For a complete list of changes in this maintenance release, please see the release notes. Due to an issue that only came to light just after the rc process, the download is for 0.19.0.1 instead of 0.19.0.

If have any questions, please stop by the #bitcoin IRC chatroom (IRC, web) and we’ll do our best to help you.



from Bitcoin Core https://ift.tt/35tlCLb

Saturday, 23 November 2019

Friday, 22 November 2019

Mnuchin’s Number Two Says Private Cryptos Pose Threat to Government Power and Will Be Watched

The deputy secretary of the U.S. Treasury has raised the specter of a not-so-distant future when private digital currencies have stripped some of the power from governments. Policymakers will take a "hard look" at that, he said.

from CoinDesk https://ift.tt/37tS2XM

Thursday, 21 November 2019

Franklin Templeton Taps Wallet Service Provider to Support Tokenized Shares

Franklin Templeton Investments, the global investment firm looking to track shares of a money market fund on the Stellar blockchain, has tapped wallet service provider Curv to help safeguard its shares.

from CoinDesk https://ift.tt/2OvnWuo

China Central Bank to Set Standards for 17 Fintech Categories, Including Blockchain

The People’s Bank of China (PBoC) has an agenda to set industry standards across the financial sector, including blockchain, a senior official from the bank said on Wednesday.  Speaking at a meeting of the National Technical Committee, PBoC vice president Yifei Fan said the bank aims to better regulate new technologies applied across the financial […]

from CoinDesk https://ift.tt/33akhY5

Wednesday, 20 November 2019

Tuesday, 19 November 2019

Fidelity Digital Assets Gets NY Trust Charter to Custody Bitcoin for Institutions

The New York Department of Financial Services has granted Fidelity Digital Assets Services (FDAS) a charter to operate as a limited liability trust company to custody digital currencies and execute crypto trading.

from CoinDesk https://ift.tt/33736ad

Monday, 18 November 2019

Sunday, 17 November 2019

Saturday, 16 November 2019

Friday, 15 November 2019

Thursday, 14 November 2019

Wednesday, 13 November 2019

Tuesday, 12 November 2019

Monday, 11 November 2019

CVE-2017-18350 Disclosure

Disclosure of the details of CVE-2017-18350, a fix for which was released on November 6th, 2017 in Bitcoin Core version 0.15.1.

Technical Details

CVE-2017-18350 is a buffer overflow vulnerability which allows a malicious SOCKS proxy server to overwrite the program stack on systems with a signed char type (including common 32-bit and 64-bit x86 PCs).

The vulnerability was introduced in 60a87bce873 (SOCKS5 support) and first released in Bitcoin Core v0.7.0rc1 in 2012 Aug 27. A fix was hidden in d90a00eabed (“Improve and document SOCKS code”) released in v0.15.1, 2017 Nov 6.

To be vulnerable, the node must be configured to use such a malicious proxy in the first place. Note that using any proxy over an insecure network (such as the Internet) is potentially a vulnerability since the connection could be intercepted for such a purpose.

Upon a connection request from the node, the malicious proxy would respond with an acknowledgement of a different target domain name than the one requested. Normally this acknowledgement is entirely ignored, but if the length uses the high bit (ie, a length 128-255 inclusive), it will be interpreted by vulnerable versions as a negative number instead. When the negative number is passed to the recv() system call to read the domain name, it is converted back to an unsigned/positive number, but at a much wider size (typically 32-bit), resulting in an effectively infinite read into and beyond the 256-byte dummy stack buffer.

To fix this vulnerability, the dummy buffer was changed to an explicitly unsigned data type, avoiding the conversion to/from a negative number.

Attribution

Credit goes to practicalswift for discovering and providing the initial fix for the vulnerability, and Wladimir J. van der Laan for a disguised version of the fix as well as general cleanup to the at-risk code.

Timeline

  • 2012-04-01: Vulnerability introduced in PR #1141.
  • 2012-05-08: Vulnerability merged to master git repository.
  • 2012-08-27: Vulnerability published in v0.7.0rc1.
  • 2012-09-17: Vulnerability released in v0.7.0.
  • 2017-09-21: practicalswift discloses vulnerability to security team.
  • 2017-09-23: Wladimir opens PR #11397 to quietly fix vulnerability.
  • 2017-09-27: Fix merged to master git repository.
  • 2017-10-18: Fix merged to 0.15 git repository.
  • 2017-11-04: Fix published in v0.15.1rc1.
  • 2017-11-09: Fix released in v0.15.1.
  • 2019-06-22: Vulnerability existence disclosed to bitcoin-dev ML.
  • 2019-11-08: Vulnerability details disclosure to bitcoin-dev ML.


from Bitcoin Core https://ift.tt/2X2LomE

Sunday, 10 November 2019

Saturday, 9 November 2019

Friday, 8 November 2019

Thursday, 7 November 2019

Crypto-Friendly Silvergate Bank Goes Public on New York Stock Exchange

Silvergate Bank, a crypto-friendly bank, officially began selling shares on the New York Stock Exchange Thursday. Roughly a year after it first filed for its initial public offering, Silvergate began its “IPO day” on the NYSE, according to the stock exchange’s Twitter account. The news comes a day after Silvergate received a “notice of effectiveness” […]

from CoinDesk https://ift.tt/2oWA2nH

Wednesday, 6 November 2019

First-Time Bitcoin Buyers ‘Doubled’ in Square’s Q3 Report

Square processed $148 million in bitcoin sales in the third quarter of 2019. The payments company, founded by Twitter co-founder Jack Dorsey, released its earnings results on Wednesday, reporting revenues of $1.27 billion between July 1 and Sept. 30 of this year. Though Square’s crypto business remains a niche concern for the publicly traded company, […]

from CoinDesk https://ift.tt/2WOe02S

Tuesday, 5 November 2019

Monday, 4 November 2019

Sunday, 3 November 2019

Saturday, 2 November 2019

Friday, 1 November 2019