Oddbean new post about | logout
â–² â–¼
 LNbank Vulnerability Recap: Last week, a critical vulnerability was identified in the LNbank plugin, which I developed as a plugin for @btcpayserver. The following post aims to outline what transpired and steps I, as a maintainer of the plugin, and BTCPay Server team are taking to prevent similar occurrences in the future. https://d11n.net/lnbank-vulnerability-recap 
â–² â–¼
 I'm sorry for all the have lost Bitcoin, but am also sorry for what you went through with this vulnerability. I know how much of your heart and soul you have put into this plugin over the years with the best of intentions.

Thank you for your contributions Dennis 🫂 
â–² â–¼
 I was not affected, but I read stories of those that were. They'll appreciate it he apology and the gesture. Thanks for the post mortem. 
â–² â–¼
 💚🫂 
â–² â–¼
 Thank you @d11n. Appreciate all that you do for Bitcoin. 
â–² â–¼
 We appreciate everything you do for Bitcoin Dennis 💚 
â–² â–¼
 Thank you very much for hanging in with this and work tirelessly to identify the source of the bug and fix it asap. Thank you for developing this great plugin in the first place. 

It shows that we need to care more for the software we use and help reviewing code and doing more adverserial testing or help in any other way to improve it.

You mention that people can donate sats to distribute to people affected, where can we do that? Zap on this post or any special lnaddress or something?  
â–² â–¼
 You can donate to @Hugo Ramos via the Lightning Address hugo@wallets.fyoumoneypod.com or onchain to bc1qz8dxk6h8gha5qvsnw67rjzz3xn6t4k0wmafqz3. 
â–² â–¼
 Related, can you explain why BTCPay asks for an admin macaroon in order to connect a remote LND instance? Shouldn't a read-only macaroon with invoice permission suffice? 
â–² â–¼
 Iirc we need it to access the connection details and health status of the GetInfo call. However, by now LND support baking custom macaroons and I'll look into if and how we can leverage that. /cc @kukks @NicolasDorier 

https://docs.lightning.engineering/lightning-network-tools/lnd/macaroons#docs-internal-guid-7b736a99-7fff-4c6f-a308-73da0d74c992 
â–² â–¼
 At this point, it's not that big of a deal to not ask for it, maybe we can drop the requirement for the info. 
â–² â–¼
 fyi working on it here. Using invoice.macaroon suffices, only downside is we cannot display the connection details on the public Lightning node info page. https://github.com/btcpayserver/btcpayserver/pull/5567 
â–² â–¼
 Thank you for the recap!
Indeed these things can happen, but working and solving issues in the open  teaches and benefits everyone.
While also being sorry for the losses I am looking forward to what more you are building! 💚💚💚 
â–² â–¼
 You’re the man, Dennis. Thanks for all your amazing work. 
â–² â–¼
 I am setting it up with LNBank on BTCPay Server. However, in light of recent revelations, I am rethinking this decision. 

nostr:note1fmtv040cm8krqzuwyt4m6kq3dmjsj28cykx45xj93g3g2dl6g4tqvk2wfc