Bitcoin Core v32 integrates privacy fix as v31 patch stays open

A privacy fix has been integrated into Bitcoin Core’s 32.x source branch to resolve a behavior that could potentially link private-broadcast connections with standard node connections. As of Oct. 8, the backport for version 31.x is still open, meaning users who activate the feature on the current stable release, 31.1, are waiting for the patch. The private broadcast setting is turned off by default.

The backport submitted on Oct. 1 incorporates the initial modification, which was merged into the main development branch on Sept. 25. A separate pull request to apply the fix to 31.x gained approval from reviewer vasild on Oct. 6 and is tagged with a 31.2 milestone, though this assignment does not set a specific release date.

The official download portal continues to show 31.1 as the most recent version. Meanwhile, the 32.0 download directory features test candidates rather than finalized release files, which include release candidate 3 (rc3) binaries bearing the date Oct. 6.

Related Reading

Major Bitcoin Core update changes default wallet protocols, risking temporary disruption across popular apps

The opt-in path at risk

Individuals activate the privatebroadcast setting for transaction submissions handled via sendrawtransaction, the command utilized to broadcast a raw transaction to the network. This specific route relies on dedicated, temporary connections linked to Tor or I2P peers, or to IPv4 and IPv6 peers routed through Tor. The connection-correlation issue impacts this specific private-broadcast functionality rather than standard nodes operating under default configurations.

Related Reading

Bitcoin Core feature freeze nears as rebase issues hit unencrypted-connection proposal

The core of the issue centers on “discouragement,” which is how Bitcoin Core manages certain poorly behaving peers and its other connections. Reviewers who assessed the original patch noted that penalizing a private-broadcast peer could trigger outward signs of altered node behavior. Standard discouragement procedures might also terminate other connections tied to that exact peer address. Such overlapping consequences could furnish an external observer with clues connecting the private channel to standard node operations.

The updated patch decouples these actions. Private-broadcast peers are now shielded from standard discouragement protocols, while misbehaving private peers are still dropped. In the same vein, penalizing a regular peer no longer severs private-broadcast connections that happen to share its network address.

Release notes for Bitcoin Core 31.1 reference a previous IP-address vulnerability where, under certain conditions, private-broadcast traffic leaked onto the clearnet instead of utilizing the designated privacy network. While that earlier fix corrected routing mechanics, the newer update targets the external visibility of peer management routines.

Additionally, developers have labeled private broadcast as experimental, tempering its privacy expectations down to risk mitigation. For operators utilizing the legacy branch, the remaining path forward involves finishing the 31.x backport and rolling out a subsequent release containing it.

Related Reading

Bitcoin Core’s new fix closes gap that could redirect funds without stealing keys

Leave a Reply

Your email address will not be published. Required fields are marked *