tag-security icon indicating copy to clipboard operation
tag-security copied to clipboard

Add Monero to Supply Chain Compromises

Open maltfield opened this issue 3 years ago • 7 comments

This curated list of Supply Chain Compromises is awesome, thanks for maintaining it!

  • https://github.com/cncf/tag-security/tree/main/supply-chain-security/compromises

I noticed that the Monero wallet's compromised release from 2019-11-18 is not listed in this repo.

  • https://github.com/monero-project/monero/issues/6151

Considering that Monero is widely considered to be the most popular/secure privacy cryptocurrency, it's easily one of the most security-critical packages that you wouldn't want to become victim to supply chain attacks..

Fortunately, they did have release signing in-place, so users were quickly able to identify the issue and address it. But it's yet another cautionary tale for project maintainers that blindly trust their infrastructure.

Further reading on this incident:

  • https://web.getmonero.org/2019/11/19/warning-compromised-binaries.html
  • https://old.reddit.com/r/Monero/comments/dyfozs/security_warning_cli_binaries_available_on/
  • https://thehackernews.com/2019/11/hacking-monero-cryptocurrency.html

maltfield avatar Nov 27 '21 13:11 maltfield

This issue has been automatically marked as inactive because it has not had recent activity.

stale[bot] avatar Jan 28 '22 15:01 stale[bot]

@maltfield thanks for opening the issue - would you be willing to make a PR for this?

lumjjb avatar Feb 16 '22 18:02 lumjjb

This issue has been automatically marked as inactive because it has not had recent activity.

stale[bot] avatar Apr 17 '22 18:04 stale[bot]

@lumjjb I would like to help to do this PR

krol3 avatar Jun 11 '22 14:06 krol3

This issue has been automatically marked as inactive because it has not had recent activity.

stale[bot] avatar Aug 12 '22 04:08 stale[bot]

@lumjjb can the PR be reviewed so this can be closed?

maltfield avatar Aug 14 '22 12:08 maltfield

sorry that i missed this - i added a comment and updated the branch.

Once we address the comments and CI passes ill merge it!

lumjjb avatar Aug 14 '22 14:08 lumjjb