Comments (1)
For the 1.0 release we probably won't have the resources to analyze this in detail. Therefore I recommend we be conservative and tell people that until further we evaluate things further...
- An attacker running on the same hardware (either in another process within the same OS, or inside another OS on a virtual machine on the same system) or who can observe nearby EM emissions from the machine can learn all of the secret inputs to a pour they watch happening through cache side channels, etc.
- Same thing for an attacker who can induce and time a small number of pours over the network (Nathan's brainstorm example above).
I suspect 1 and 2 are false, for example some secret inputs like rho are only input to a pour once so it's hard to get multiple samples, but until we know more we should assume they are true and advise our users to behave accordingly.
from zcash.
Related Issues (20)
- Add tex addr support in validateaddress rpc
- Add support for Debian in GitHub Actions HOT 1
- zcashd crash when run "zcash-cli z_sendmany" HOT 1
- [zcashd book] Document that Debian Bookworm is a tier 1 platform HOT 1
- Release 5.10.0
- Deploy NU6
- Zcashd Audit for NU6 Release
- `cargo-deny` has MSRV 1.74, which is inconvenient since zcashd has 1.69.0 in `rust-toolchain.toml`
- Document in 5.9.0 release notes that macOS support is being dropped to Tier 3 in 5.10.0
- Drop Intel macOS to Tier 3
- Deprecate zcashd
- Ensure that last release of zcashd EoS-halts before the first incompatible NU activates
- Zcashd consensus implementation for NU6
- Enumerate the data / state that needs to be migrated from `wallet.dat` to a future full node wallet
- Docker image should not run zcutil/fetch-params.sh
- Reuse previous build artifacts if they are available and their inputs are unchanged
- Validate Sapling outputs of coinbase transactions according to ZIP 212
- Remove the default unpaid action limit HOT 2
- Don't accept to mempool and don't relay TX with zero fees HOT 1
- How do I upgrade to the new version? Now it is 5.8.0 I do as instructed: git fetch origin, then git checkout v5.9.0 and other commands. The version is still running 5.8.0. I uninstalled the zcash folder, tried installing again, tried 5.9.1 - still runs 5.8.0. What is wrong?
Recommend Projects
-
React
A declarative, efficient, and flexible JavaScript library for building user interfaces.
-
Vue.js
🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.
-
Typescript
TypeScript is a superset of JavaScript that compiles to clean JavaScript output.
-
TensorFlow
An Open Source Machine Learning Framework for Everyone
-
Django
The Web framework for perfectionists with deadlines.
-
Laravel
A PHP framework for web artisans
-
D3
Bring data to life with SVG, Canvas and HTML. 📊📈🎉
-
Recommend Topics
-
javascript
JavaScript (JS) is a lightweight interpreted programming language with first-class functions.
-
web
Some thing interesting about web. New door for the world.
-
server
A server is a program made to process requests and deliver data to clients.
-
Machine learning
Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.
-
Visualization
Some thing interesting about visualization, use data art
-
Game
Some thing interesting about game, make everyone happy.
Recommend Org
-
Facebook
We are working to build community through open source technology. NB: members must have two-factor auth.
-
Microsoft
Open source projects and samples from Microsoft.
-
Google
Google ❤️ Open Source for everyone.
-
Alibaba
Alibaba Open Source for everyone
-
D3
Data-Driven Documents codes.
-
Tencent
China tencent open source team.
from zcash.