Comment 3 for bug 1803914

Revision history for this message
Matt Corallo (bluematt) wrote :

(a) "BitcoinUnlimited" is a wholly different project from Bitcoin-Qt. Squatting on the "bitcoin-qt" name (which is a standard package in Debian Testing/used to be in Ubuntu/the Bitcoin Core PPA) to ship Bitcoin Unlimited (an unrelated software project) is definitely not OK. Further, Bitcoin Unlimited is fundamentally insecure, see https://eprint.iacr.org/2017/686.pdf.

(c/d) So is the "bitcoin" snap publishing Bitcoin Classic, or is it publishing software from the Bitcoin Core project, as the name implies?

Historically, Ubuntu/Debian shipped Bitcoin Core packages with other packages, but those were removed at the request of upstream due to the unique nature of Bitcoin both as a financial system as a consensus system putting users at needless risk when updates are not made available in a timely fashion.

In that context, I think it should be pretty obvious that snaps which control/manage peoples' Bitcoin, especially full node versions thereof, uploaded by individuals unrelated to the projects in question is really not OK and a real risk for Ubuntu users.