spesmilo / electrum

Electrum Bitcoin Wallet
https://electrum.org
MIT License
7.45k stars 3.09k forks source link

Comprehensive documentation/labelling of past security vulnerabilities? #4495

Open will-ca opened 6 years ago

will-ca commented 6 years ago

Is there a comprehensive list of past security weaknesses and the version they were fixed in anywhere?

For example, I notice that there is a security label in the issue tracker here, which should in theory provide such a list.

When I search for it, however, I also notice that issue #3374— a critical security flaw by any reckoning— is not properly tagged.

As a new user, this immediately raises alarm bells for me: If information on known vulnerabilities is not properly indexed and publicly available, then how can I be sure that I've done everything I can to protect my funds? It makes it difficult to make informed decisions and IMO it hurts credibility as well since such critical information shouldn't be left unorganized.

Proper tagging of issues on this issue tracker would fix this, as could a dedicated page in the documentation.

IDK if this is maybe not an issue because there haven't been any other critical security flaws; but then again, I can't know because there doesn't seem to be much documentation or organization in that regard.

SomberNight commented 6 years ago

We only started tagging issues recently. Do you have the time to go through 4000+? :)

AbdussamadA commented 6 years ago

The release notes are informative: https://github.com/spesmilo/electrum/blob/master/RELEASE-NOTES