Comment 13 for bug 1803914

Revision history for this message
Matt Corallo (bluematt) wrote : Re: [Bug 1803914] Re: bitcoin namesquatting

Those release notes are for the *upcoming* 0.17.1 release which is currently in the RC process (and likely to be released next week).

> On Dec 13, 2018, at 15:37, Gal Buki <email address hidden> wrote:
>
> The release notes say that it's version 0.17.1
> https://github.com/bitcoin/bitcoin/commit/ef70f9b52b851c7997a9f1a0834714e3eebc1fd8
>
> --
> You received this bug notification because you are subscribed to the bug
> report.
> https://bugs.launchpad.net/bugs/1803914
>
> Title:
> bitcoin namesquatting
>
> Status in Snap Store:
> New
>
> Bug description:
> There doesn't appear to be a place to report this kind of thing, but
> at least https://snapcraft.io/bitcoin-qt appears to be some random
> package which isn't a released version and at least
> https://snapcraft.io/bitcoin, https://snapcraft.io/bitcoin-ec, and
> https://snapcraft.io/bitcoin-unlimited are (a) significantly out-of-
> date, (b) have outstanding major CVEs against them, (c) (for the
> "bitcoin" snap) actually shipping software which is different from
> what is claimed by the description (at least if the developer
> website/contact link is correct), (d) don't have a valid contact link
> for the developer, (e) a massive security risk for users, given the
> random individual appears to be able to push updates which arbitrarily
> steal users' money.
>
> It seems massively dangerous that someone can come along and upload a
> "bitcoin" package and get users to install it when it is clearly
> bogus, especially when the Bitcoin Core project (which is being
> imitated here) has an officially-supported Bitcoin PPA (see
> https://bitcoincore.org/en/download/)! How do we get these snaps taken
> down and prevent people from uploading bitcoin/bitcoin-qt/bitcoin-
> core/etc snaps in the future?
>
> To manage notifications about this bug go to:
> https://bugs.launchpad.net/snapstore/+bug/1803914/+subscriptions