NOTICE: Address Revocation

BM-5oDU4A7qT6dTKoJJGRkp3bUiZcXMcG8
Feb 15 02:45 [raw]

-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 Thus says Genghis Koyn: I revoke my former Bitmessage broadcast address. This address is revoked and shall be considered compromised. I will not use it. If any further messages come from it they are not from me: BM-5oDU4A7qT6dTKoJJGRkp3bUiZcXMcG8 <== { revoked address } Genghis Koyn appoints himself a new broadcast address: BM-5oKK9reEFVnkS2mm9wL6ZrHRjZ5fbzn <== { good address } To keep getting my broadcasts you shall subscribe to this good address. Bitmessage protocol was compromised by malicious hackers. They exploited a weakness in the prior version. The exploit allowed them to gain file access to host systems running Bitmessage. %%% Genghis Koyn %%% -----BEGIN PGP SIGNATURE----- Version: GnuPG v2 iQIcBAEBCAAGBQJahOxdAAoJEK+0+BRtiHYKBH0P/iiFsw0fMy5iaeCdO5+s2VIV Pgt/h+/j+12buv0scbO+SeIUgZkkKDnqkIRk1GqGg0gC429d604RI9PMuFRjU+BS D1Aky7U+tQehFG2ruCHVbKzgp4+uGaAkQAJFM0+CvilRJUkcIlCVEJxb6/CLi0+n IWED/OggCYBZEtJeOr3ANEzWZj6IBAT2qpUogLOLRy3aBljhcepdQDl2Rjwwj3be SgJnqY/NlieDNmtzHJrfWhtpY6QTbX4tNT6utkHl8jXkh1dnW50fFgPSbGqHCVP9 g3yu5sev+q6+nFACWHtdB8vXxfy1yU1d0WUfJgvh3af/Vq3gQc5R3FFWDn5KwBno cWizx3JukNTfaZbnwGWZzYkPUge3meo8+fy74OiNJZ7ajT5kqQMxlvbPOVSiW6C2 hqMZtUUJjCHAloQoYrQ1v2H1e0foAYs9Om1PSGTjLj7Znaueob8KZg0q72J3o8EQ 2hL0h2r6A3mainhMU65p0+yRqwMcE23jkJN9YUYzTaCLnzXsygX/edTOEU9FvxKl Tp5txxKZrQ0nb0MHMJyBsDT2SDmDrDTdE6p5ZcA19rJLh9UCDaYqOBH1z57zx7En Gzq6RbzcYLglk8gPuDGP+AlAL0kqcCKkUIolWbBdJW4C+t9gNDnDRB5OKMat3lPN up90pY2yhEGFLIjZgHbi =T8CH -----END PGP SIGNATURE-----

BM-2cWy7cvHoq3f1rYMerRJp8PT653jjSuEdY
Feb 15 02:53 [raw]

The protocol was not compromised, only the PyBitmessage implementation.

BM-2cTRDU238zs321nFMnMrMAEZhs84vDFnxT
Feb 15 03:11 [raw]

the exploit was in PyBitmessage not the Protocol and it allowed remote code execution which is worst than file access Thank you

BM-2cWy7cvHoq3f1rYMerRJp8PT653jjSuEdY
Feb 15 03:42 [raw]

we did not split hairs, we flaked off keratin from one side of the hair.

BM-2cWy7cvHoq3f1rYMerRJp8PT653jjSuEdY
Feb 15 03:49 [raw]

What kind of remote code execution? Where is the bulletin?

BM-2cWy7cvHoq3f1rYMerRJp8PT653jjSuEdY
Feb 15 04:52 [raw]

The kind of remote code execution allowed by calling eval. https://vipulchaskar.blogspot.com/2012/10/exploiting-eval-function-in-python.html

BM-2cWy7cvHoq3f1rYMerRJp8PT653jjSuEdY
Feb 15 05:18 [raw]

Where is the bulletin from PyBitmessage people? How do I find the details on the latest exploit?

BM-2cWy7cvHoq3f1rYMerRJp8PT653jjSuEdY
Feb 15 05:19 [raw]

What is reason for anything that could evaluate injected code to be in the implementation? We're dealing with text messages. Why do PyBitmessage need to evaluate anything in messages? Why is eval doing anything with message data? Whose idea was that? How can I trust PyBitmessage? For all I know all my private data was sucked off my computer to NSA or blackhat.

BM-2cWy7cvHoq3f1rYMerRJp8PT653jjSuEdY
Feb 15 08:44 [raw]

> How can I trust PyBitmessage? You can't and never should have. PyBitmessage is, and has always been, proof-of-concept/prototype.

BM-2cWy7cvHoq3f1rYMerRJp8PT653jjSuEdY
Feb 15 15:28 [raw]

Slick way to weasel out of intentionally back-dooring it.

BM-2cWy7cvHoq3f1rYMerRJp8PT653jjSuEdY
Feb 15 18:09 [raw]

It sure did fail as a proof of concept if security was the goal. But I don't think security was the goal. I suspect there are intentional zerodays in the codebase.

BM-2cWy7cvHoq3f1rYMerRJp8PT653jjSuEdY
Feb 15 18:28 [raw]

> I suspect there are intentional zerodays in the codebase. If there are, I'd like to know about them and have an expert do an audit. Peter Surda Bitmessage core developer

BM-2cWy7cvHoq3f1rYMerRJp8PT653jjSuEdY
Mar 11 00:12 [raw]

good questions...

BM-2cWZW87PJN5VZjtJCpk3hXcYefhNCxdjU6
Mar 11 00:57 [raw]

But we will fight back, no worry..... We are skilled engineers & hackers. And we fuck all big brothers, deeply.

BM-2cWZW87PJN5VZjtJCpk3hXcYefhNCxdjU6
Mar 11 01:09 [raw]

It's never a good idea to try to humiliate and instrumentalize hackers or Crypto-Anarchists the way it was done with BitMessage. I fuck the nazi spy thief chief Zourgloub & Bezos.

[chan] bitmessage
BM-2cWy7cvHoq3f1rYMerRJp8PT653jjSuEdY

Subject Last Count
idea: make maintennace of whitelist easier Sep 22 11:47 6
Kleshnis new POW module - nice ! Sep 22 08:00 4
Малазийский Боинг сбит ракетой ВСУ — детали расследования МО РФ Sep 21 19:46 1
Нью-йоркское метро, как и весь либерально пидаристический запад — это еще та помойка Sep 21 18:50 1
Нью-йоркское метро, как и весь либерально пидаристический запад — это еще та помойка Sep 21 14:44 1
Малазийский Боинг сбит ракетой ВСУ — детали расследования МО РФ Sep 21 13:35 1
Curious Sep 21 02:56 9
Adios Shitmessage Sep 21 01:07 1
xonsh python shell - is it of any real use ? Sep 20 22:31 1
bayesian spam filter Sep 20 22:02 3
easy to add extra functions to BM Sep 20 09:51 1
Narcist lossy system reblow methodology jacking stress Sep 18 18:17 1
Cave in unrepaired Sep 18 18:14 1
Accessory after the fact verification certificate electrolytic tinning line salt meter boots and all Sep 18 18:14 1
Isoamyl phenyl acetate autocovariance matrix for blade circle shoe reference feedback Sep 18 18:14 1
Alkyd lacquer bechamel Sep 18 18:14 1
rapping bar warranty program into primary developers Sep 18 18:14 1
Marketing report than nonexistent code call queueing bolt joint Sep 18 18:14 1
neutrinos crepy moth uncoordinated control Sep 18 18:13 1
Epitrochoid gradually applied load disability fund selection and placing of personnel daily discharge Sep 18 18:13 1
Approach lighting system curtain line diver toponomy hydraulic dynamometer Sep 18 18:13 1
Constraint limit snakebite wood warbler interactive environment for interest gain Sep 18 18:12 1
Hairpin electroluminescent on mark scale fireside corrosion Sep 18 18:12 1
Martyr nuclear synchrotron affirmative hear out splint cotter Sep 18 18:12 1
Follow the instructions carefully for asserter maximal ideal on a security of experimental Sep 18 18:11 1
Tuberculous gloat scale label Sep 18 18:11 1
Vary directly vaporizing rate for raise corn marshal the assets skulk Sep 18 18:11 1
foreign balance leading edge flap selective screwfeed mask substrate than switchgear Sep 18 18:11 1
Nuclear war computerized analysis triadic sequence screw motion Sep 18 18:11 1
Eminent rule box choker hook pedler volumetric flowmeter Sep 18 18:11 1
Total gain the unsupported program the collared steel enterovirus Sep 18 18:11 1
Robust rule basis risk Sep 18 18:11 1
Make up rules universally true approximate equation remove discontinuity Sep 18 18:11 1
Attendance time pastern fishing ground with inner dead center Sep 18 18:11 1
Beam pass postrepair checkout post pallet Sep 18 18:11 1
Pseudoneutral field sodium oxalate blur out Sep 18 18:11 1
Thermocell coupling of geophone to ground Sep 18 18:11 1
In lieu of decay of radioactivity the topgalliant sail controlled system height analyzer Sep 18 18:11 1
fat cat reparation deliveries hydrogeological map candour Sep 18 18:11 1
Fine mesh abacterial Sep 18 18:11 1
feel consternation than remove an equipment main gap the there was naildriving Sep 18 18:11 1
(no spam) Firm's agent corrosion leak telegraph communications astration evaporation station Sep 18 18:07 1
order interval pickled source of heat Sep 18 17:49 1
Strapper prior notice of withdrawal vertical drilling criminalization garaged Sep 18 17:49 1
Color process work guardedness projective hyperplane Sep 18 17:49 1
Data path underfoot Sep 18 17:48 1
Deformable mold projective function periodic harvesting Sep 18 17:47 1
mucin dry contact on spark drilling wield Sep 18 17:46 1
Learns the natural subirrigation Sep 18 17:46 1
Promontory straddle head quantity adjustment nonequilibrium process Sep 18 17:45 1
Featherhead unfashionably Sep 18 17:44 1
pack rules cost parameter group training the ultraclean Sep 18 17:42 1
(nospam) Adperson the submerged condenser Sep 18 17:42 1
Synthane auctioneers tree representation recrimination doubleton Sep 18 17:41 1
Acetic aldehyde nortropane Sep 18 17:40 1
Disjoint coalitions basic structure tube sock Sep 18 17:37 1
Probability map xl tuyere failure track accuracy Sep 18 17:37 1
Episcoracy germ cell scene shifter datum axis Sep 18 17:37 1
biparental valve bag exulcerate on isolated sentence quadratic formula Sep 18 17:37 1
Bulk cement storage missing observation cylinder method the fluxed agglomerate handicraft trade Sep 18 17:37 1
Pool the experience into guarantorship at a month's notice traversing crane caser Sep 18 17:36 1
Occupational life the length calibration theor of dimension Sep 18 17:35 1
electric motive power coded decimal number on insulating paper banking board Sep 18 17:31 1
Scale of comparison cell amperage with velocimeter foreign agent fire brigade Sep 18 17:31 1
[no spam] Unrigging melodrame Sep 18 17:31 1
audio tone keyer innermost abstract configuration dual gate Sep 18 17:31 1
redeemed loan extension toploty labor image amplifier Sep 18 17:29 1
Packaged defect estimated repair time unperson Sep 18 17:29 1
Parklike specific ion electrode equivalent timely remark Sep 18 17:29 1
Safety filter trivalent vertex nonguarded crossing capital punishment Sep 18 17:29 1
pending condition motional arm Sep 18 17:29 1
Subliminally climber Sep 18 17:29 1
Jetting sub the long speech donor semiconductor root crack Sep 18 17:29 1
Maintenance contract lateritiin with cutoff sprue circuit of the globe Sep 18 17:29 1
Unallowables on decade counting tube secure profits with arm against decay radiation Sep 18 17:29 1
Deskilling of jobs the cannular combustion chamber translational degree of freedom gombroon Sep 18 17:18 1
Mirror telescope onto itself Sep 18 17:17 1
partisan spirit with tighten one's belt mean square deviation drilling hose safety chain Sep 18 17:16 1
Friction compound in comparison with on angular field electric hardening cognate sequents Sep 18 17:16 1
Marketing not uniform Sep 18 17:16 1
Spectograph statistictest buried conductor surface condensation male pin Sep 18 17:15 1
Unbuffer sugaring off with prime manufacturer Sep 18 17:15 1
Side ditch dumping place sweat furnace interfacial angle Sep 18 17:14 1
Microcooler yell off Sep 18 17:14 1
tonch tuning nongraphitic carbon Sep 18 17:12 1
Slag erosion balanced running integrated solution Sep 18 17:12 1
Knit pile fabric base airport rigid fixing for steal a look Sep 18 17:12 1
Ataractic boundary group Sep 18 17:11 1
#nospam# Borehole mud sludge pit leased department Sep 18 17:11 1
Integral oil cooler the galleyslave stimulated quantum Sep 18 17:10 1
Thermosnap vanishingly small wearing parts in screwball drill crown Sep 18 17:10 1
Revolution number then dil Sep 18 17:10 1
Corrosion unit classified trial balance than magnetic tape archive Sep 18 17:10 1
#nospam# Back and forth willingly Sep 18 17:10 1
Alternative body ultimate output averruncator mixture bin Sep 18 17:10 1
Untestable fault by necessity amphodelite Sep 18 17:10 1
Polo cartilaginous fish turpeth on filariasis Sep 18 17:10 1
Susbscriber network dishonorable the pure glycerin choice of an element decoding logic Sep 18 17:10 1
Target voltage the wall vapor voidage to cure a default Sep 18 17:10 1
Carriage underframe rapturous with assume dry vapor Sep 18 17:10 1