Skip to content

Document general attacks on privacy and security #565

Open
@ariard

Description

@ariard

We should add a SECURITY.md exposing all privacy/security issues while implementing a lightning client and requirement to mitigate them.

To mention:

  • payment_secret secure randomness
  • broadcasting interface privacy leaks (end-goal is to internalize it but right now it's up to the user)
  • ChainWatchInterface and chain backend security tradeoffs
  • utxo pool size/population when CPFP
  • channel parameters value (congestion, dust inflation)
  • watchtower integration
  • key interface and key management
  • ChannelMonitor consistency and storage

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions