"The wallet pings an onion URL to check for a new version"

So let me tell you how this can all go wrong.

From clearnet to Tor username resuse, to social engineering attacks (and lastly actual exploits" there are a lot of ways to reveal the identity of the developers and get into the server that hosts the updated program.

If a whole userbase that doesn't want their ID tied to their Bitcoin transactions is using this software for that purpose, and among that userbase is a criminal of any sort, then a malicious update to deanonymize the entire userbase is a real and persistent threat.

nostr:nevent1qqsr7uupgfw39zv4ee20pt5y88khz0cc7qt753cf4uaurx66n8xe2hcpp4mhxue69uhkummn9ekx7mqpz3mhxue69uhhyetvv9ujuerpd46hxtnfduq32amnwvaz7tmjv4kxz7fwd4hhxarj9ec82cspzemhxue69uhhyetvv9ujuurjd9kkzmpwdejhgqgnwaehxw309aex2mrp09skymr99ehhyecllq5qv

Reply to this note

Please Login to reply.

Discussion

No replies yet.