🚨 BTCPay Server ≤ v2.4.1 critical TOTP 2FA bypass.
https://t.co/h2hpAPW5HL
Root cause:
the Greenfield Basic auth handler was refactored from PasswordSignInAsync() which implicitly enforces 2FA to CheckPasswordSignInAsync(), which only checks the password.
explicit MFA guard covered FIDO2 keys only, never TOTP.
Result: email + password = full API access with an unrestricted permission claim, even on 2FA-protected accounts. Actively exploited in the wild.
@stephanlivera Becoming the settlement layer IMO: exchange batch withdrawals, ETF balancing, treasury companies etc etc. Tradfi norms, processes etc have taken the transaction volume off chain, aggregated it, and only net settlement occurs on chain as needed. L2 do the same.
@CitizenBitcoin@L0RINC Datacarriersize still configurable in v30 for aggregate amount of allowed data per transaction (as multiple OP_RETURN outputs per transaction are supported) but marked as deprecated, is my (very limited) understanding
For the first time in my life I just drove a keyless modern car that told me what to do, and had tons of small things I couldn’t override — when to put on brights, when to speed up suddenly, all in the name of the safety algorithm, etc — and I’m surprised with how angry and sad it made me
@LogTech1999 Fantastic teacher. Vivid memories of his systems dynamics course at Sloan introduced with a great game demonstrating the build up of traffic jams
@SwaledaleMutton@Cynfab3 Perhaps some downsides for the cattle which may only occur longer term. Microbiome disruption is rarely without consequence https://t.co/O5nNdP8UXW
@JoshMandell6 @ChuckDieselETH Believe it’s possible to pay dividends in specie under US law subject to articles of association and shareholder approval. NOT a lawyer
No, this is wrong.
The reason there are fewer euro transactions going over SWIFT is because Europe's new large-value payments system, T2, added a second access point in addition to SWIFT, called SIAnet. In short, euro payments are increasingly bypassing SWIFT.