Damus
HODL · 1w
Worth a read https://insider.btcpp.dev/p/when-randombytes-runs-but-doesnt?r=2jfs7&utm_campaign=post&utm_medium=web&triedRedirect=true
zaytun profile picture
What I dont understand is, in an industry so focused on security, how did this go unnoticed? I mean, it looks to me like basic software engineering principles were neglected, so why was that not noticed?

It might very well be that its a "hindsight is 20/20" kind of thing, but it just doesnt seem like the bug was really all that hard to identify.

There has been attempts to make this seem like it was only possible to identify this bug with amazingly intelligent cutting edge AI, but it kind of seems more likely to me that *no one* actually even took the time to review the code at all before this event.

Now that all hell broke lose, it seems so trivial to identify the bug.

Obviously, also in hindsight, it is so easy to see the red flags of NVKs arrogance, finger-pointing, whining about people building on top of his ideas and especially the "open verifiable" disaster.

❤️1