electrs icon indicating copy to clipboard operation
electrs copied to clipboard

Can an elects-server or a bitcoin-node be exploited if exposed to the internet?

Open stn021 opened this issue 2 years ago • 2 comments

Hello, I have installed electrs, a bitcoin-node and the btc-rpc-explorer. All work. Thank you to romanz and all contributors for electrs.

I would really like to use the server with all these programs not only at home but also elsewhere. For that case there are warnings to do this only with protection-schemes like a tor-service and firewall and authentication etc.

In my case there are no active wallets involved, so no keys can be stolen. I am not aware that any private or confidential information is stored. All three programs simply access the publicly available data on the bitcoin-blockchain.

Can an elects-server or a bitcoin-node or the btc-rpc-explorer really be misused under these conditions if somebody else logs in ?

stn021 avatar Jan 05 '23 22:01 stn021

Great to hear, thanks!

Please note that querying a history of a popular address can take a lot of CPU & I/O resources, and can be used as a remote denial-of-service vector if not handled properly. IIRC, ElectrumX is more resistant to such issues (compared to electrs).

romanz avatar Jan 06 '23 09:01 romanz

I think we should have SECURITY.md to explain all this in detail.

Kixunil avatar Jan 06 '23 17:01 Kixunil