XMR誘餌選擇算法的私密漏洞 - 數位貨幣

Andy avatar
By Andy
at 2021-08-13T15:52

Table of Contents

新聞來源連結:
門羅幣官方twitter
https://twitter.com/monero/status/1419852036913475587?s=20
門羅幣論壇

https://forum.monero.space/d/
94-privacy-bug-decoy-selection-algorithm-ignores-very-recent-outputs

新聞本文:
Privacy bug: Decoy selection algorithm ignores very recent outputs

sgp_17 days ago Edited

A rather significant bug has been spotted in Monero's decoy selection
algorithm. Please read this whole message carefully.
在門羅幣的誘餌選擇算法中發現了一個相當顯著的錯誤。

If users spend funds immediately following the lock time in the first 2
blocks allowable by consensus rules (20 minutes after receiving funds), then
there is a good probability that the output can be identified as the true
spend. This does not reveal anything about addresses or transaction amounts.
Funds are never at risk of being stolen.
如果用戶在共識規則允許的前2個區塊的鎖定時間之後立即花費資金(收到資金後20分鐘
),那麼有高機率將輸出可被識別的真正花費。這不會透露有關地址或交易金額的任何信
息。資金也沒有被盜的風險。

This bug persists in the official wallet code today. Users can substantially
mitigate the risk to their privacy by waiting 1 hour or longer before
spending their newly-received Monero, until a fix can be added in a future
wallet software update. A full network upgrade (hard fork) is not required to
address this bug.
使用者可以在花費新收到的門羅幣之前等待1小時或更久,直到可以在未來的錢包軟體更
新中添加修復程序,從而大大降低其隱私風險。解決此錯誤不需要完整的網絡升級(硬
分叉)。

The Monero Research Lab and Monero developers take this matter very
seriously. We will provide an update when wallet fixes are available. Please
read this GitHub issue for more details:
https://github.com/monero-project/monero/issues/7807

I have invited the individual who spotted this bug, Justin Berman, to join me
on an episode of Breaking Monero once we can more easily explain the required
fix to people.

評論:
大家收到XMR後記得等一下再使用就沒事了,雖然不太方便不過先頂著先。

--
If yesterday was two days ago tomorrow,
will the day after tomorrow be today or yesterday?
Temporal Manipulation 101 final exam, Tolarian Academy
如果昨天到了明天會變成兩天前,
試問後天應該是今天或是昨天?
時間操縱緒論期末考,陶拉里亞大學院

--

All Comments

Elma avatar
By Elma
at 2021-08-17T19:58
暗網表示…
Steve avatar
By Steve
at 2021-08-18T22:56
地址或金額這種重要資訊不會輸出啦,且有暫時workaround
Tracy avatar
By Tracy
at 2021-08-19T23:52
不用硬分岔的話應該都小事...
Thomas avatar
By Thomas
at 2021-08-23T09:16
再轉一個 secret network 後換乙太從 bsc 或 erc 出

十年

Lydia avatar
By Lydia
at 2021-08-13T14:24
※ 引述《albert780510 (Vio)》之銘言: : 10年之前我不認識幣 : 幣不屬於我,我們還是一樣 : 陪在一個大時代左右 : 走過大通膨熟悉的QE : http://i.imgur.com/yAfgqXq.jpg : ----- : Sent from JPTT on my Samsung S ...

十年

Una avatar
By Una
at 2021-08-12T20:09
10年之前我不認識幣 幣不屬於我,我們還是一樣 陪在一個大時代左右 走過大通膨熟悉的QE http://i.imgur.com/yAfgqXq.jpg ----- Sent from JPTT on my Samsung SM-N9860. - ...

Cryptocom加密卡,分享+心得+禮盒開箱!

Edwina avatar
By Edwina
at 2021-08-12T19:06
#複水幣圈生活應用 #cryptocom #visacard 【幣圈生活の加密卡,最潮必備 andamp; VIP開箱】 https://i.imgur.com/kVD0VnA.jpg 最潮必備: 1. 日常消費筆筆2%~8%回饋 2. 一卡在手福利滿滿,免費享Spotify、Netflix、機場貴賓等等使用 ...

加密貨幣市場的掛單 與 hodler?

Poppy avatar
By Poppy
at 2021-08-12T16:44
就是以前 做股票跟期貨總是想很多 想暗算別人 08:45就起來 掛假單 再抽單 13:25 又在那邊陰謀 最後一搓等等 抽籤的時候 故意最後一小時才去抽 漲停或跌停 或有什麼溢價的時候 前一天 就要先掛單排隊 反正搞東搞西的 每天收盤後 委託沒成交 明天就要重來 每天心態又不一樣 雖然 ...

英雄?大反派?Poly駭客已還「2.6億美元

Christine avatar
By Christine
at 2021-08-12T16:21
英雄?大反派?Poly駭客已還「2.6億美元」半數贓款 : 我寧願在黑暗中拯救世界! 創下 DeFi 史上最大盜竊案的駭客已歸還 6 億美元贓款中的 2.6 億,並在交易轉帳留言上 發布了長達三頁的自問自答 Qandamp;A、解釋自己的目的。除了對資金不感興趣外,被部分人稱 為 “Etherhoo ...