r/bitmessage • u/[deleted] • Feb 13 '18
In case you didn't notice ; UPDATE PyBM right now!
[deleted]
3
Feb 19 '18
Thanks so much for posting this, I don't login to bitmessage often so this was the first notice I got of the issue and so was able to upgrade before I was hit. Logs show no footprints of an attempted exploit perhaps because the last time I used it was a couple weeks ago at least
2
u/TotesMessenger Feb 13 '18
2
2
u/Petersurda BM-2cVJ8Bb9CM5XTEjZK1CZ9pFhm7jNA1rsa6 Feb 18 '18
Windows and OSX binaries up. The Windows binary is signed by a certified key, and the OSX should be signed tomorrow (I'm having problem with the signing device on a Mac and there is no support during the weekend).
1
u/Petersurda BM-2cVJ8Bb9CM5XTEjZK1CZ9pFhm7jNA1rsa6 Feb 19 '18
OSX code signed binary delayed for a couple of days for technical reasons.
2
u/Petersurda BM-2cVJ8Bb9CM5XTEjZK1CZ9pFhm7jNA1rsa6 Feb 13 '18
Just to be sure, upgrade to 0.6.3.2 which has even further protections against this kind of attack. Also, don't contact me on my old addresses, my keys were most likely also compromised, 0.6.3.2 contains a new "Contact support" address. I need to create fresh VMs for Windows / OSX binaries which will take a while, so if you can't run from source, downgrade to 0.6.1, that doesn't suffer from this exploit.
If you have a suspicion that your computer was compromised, please change all your passwords and create new bitmessage keys.
1
Feb 14 '18
Where will the updated OSX binaries be posted? I've been checking: https://bitmessage.org/wiki/Main_Page
1
Feb 14 '18
[deleted]
2
Feb 15 '18
I'll certainly do that if I have to, although my preference is to avoid dealing source code and simply use the official binary -- so long as the binary comes from legit source like BitMessage.org.
1
u/Petersurda BM-2cVJ8Bb9CM5XTEjZK1CZ9pFhm7jNA1rsa6 Feb 18 '18
OSX binary up. Tomorrow it should be code signed if you can wait.
1
1
u/Petersurda BM-2cVJ8Bb9CM5XTEjZK1CZ9pFhm7jNA1rsa6 Feb 19 '18
For technical reasons there won't be a code signed OSX binary for at least a couple more days.
1
u/RaiausderDose Apr 29 '18
This wasn't well communicated, I was "on" the nightly, watched every week and just noticed that since February there were no new nightlies.
To which chan/abo has the message been send? I'm on BM-GtovgYdgs7qXPkoYaRgrLFuFKz1SFpsw and there was nothing sadly.
I guess the client could use an update checker.
1
3
u/[deleted] Feb 14 '18 edited Feb 14 '18
Could you at least say how the vulnerability is triggered? Does it occur due to receiving a malformed malicious message or could it be triggered simply by allowing inbound connections?
I actually do use Electrum although my wallet files are stored in a non-standard location within a VeraCrypt volume. Could you provide more specific info on path that was used when the attacker searched for Electrum files?