IOHK Releases Cardano’s Byron Reboot Third-Party Security Audit; 11 Vulnerabilities Found

  • IOHK publishes potential vulnerabilities that are successfully resolved “to spur greater transparency and security across the industry.”
  • Cardano has released the latest version of Daedalus which is the mainnet wallet for Cardano and is faster with several improvements.

Just before entering into this month, Cardano went live with its Byron Reboot, in preparation for its transition to the Shelley mainnet.

The Reboot that took 18 months to complete was made “from scratch” and included a series of updates to the Cardano network — the node, explorer, and Daedalus wallet backend. The new design as explained by IOHK, was

“modular, separating the ledger, consensus, and network components of the node, allowing anyone of them to be changed, tweaked, and upgraded without affecting the others.”

In Cardano’s aim to maximize decentralization on its network, the Byron reboot was one step which in itself wasn’t an event but more of a process.

Now, IOHK has published 11 potential vulnerabilities uncovered and successfully resolved as well during Phase 1 and 2 of the third-party audit of the Byron Reboot “to spur greater transparency and security across the industry.”

“It is vital that the blockchain industry lives up to its own vision of open and decentralized systems when it comes to the process of building blockchains,” said Cardano creator and CEO of IOHK Charles Hoskinson.

“Companies must not prioritize secrecy and speed to market over security because vast sums of money and even lives will depend on the software we produce.”

Potential vulnerabilities successfully resolved

As of April 20, 2020, the cybersecurity company root9B (R9B) found insecure Genesis Key Generation which has now been rectified by altering the code to use secure key generation.

Just like with genesis key generation, it was found the potential protocol incompletion and primitive usage of mock crypto was only for testing and not for production use, with real implementation forthcoming.

For code practice and potential resource usage/denial of Service (DoS), R9B confirms the changes fully address issues 2, 3, and 4.

When it comes to ADA wallet, Daedalus has been fully upgraded to the Byron Reboot Era and is now up for download, tweeted Hoskinson.

The brand new Daedalus is the mainnet wallet for Cardano. Built on the new Haskell codebase, this version brings advancements in stability, reliability, and performance along with improvements in connection, blockchain synchronization & wallet restoration speed, as well as reduced memory usage, shared IOHK.

Root98 found weakened protection – CSP in Electron App but this configuration is used by IOHK until Chrome can evaluate WASM without it.

Also, Blake hash function was performed only once when applying a spending password, IOHK confirmed, “Daedalus frontend to Cardano wallet backend connection relies on TLS for password security in transmission and plans to phase out Blake hashing.”

IOHK is further planning to heed the potential future issue with payment URI for code that may encounter it and to replace the update process with a new one to be released in April 2020.

R9B has also accepted the resolution that addresses randomization is for port conflict-avoidance and that IOHK has removed the exposed surface including disabling the Monitoring Web Frontend in the configuration.

Lastly, the theoretical Denial of Service (DoS) vulnerability is expected to be fully resolved by the Ouroboros Praos private slot-leader schedule (Shelley).

Cardano (ADA) Live Price

1 ADA/USD =$0.1429 change ~ 4.06%

Coin Market Cap

$3.7 Billion

24 Hour Volume

$98.77 Million

24 Hour VWAP

$0

24 Hour Change

$0.0058

Get Free Email Updates!

*Action* Enter Best Email to Get Trending Crypto News & Bitcoin Market Updates

I will never give away, trade or sell your email address. You can unsubscribe at any time.

AnTy
AnTy
AnTy has been involved in the crypto space full-time for over two years now. Before her blockchain beginnings, she worked with the NGO, Doctor Without Borders as a fundraiser and since then exploring, reading, and creating for different industry segments.

[Alert] Use the author's self-conducted information at your own risk, do you own research, never invest more than you are willing to lose.

[Disclosure] The published news and content on BitcoinExchangeGuide should never be used or taken as financial investment advice. Understand trading cryptocurrencies is a very high-risk activity which can result in significant losses. Editorial Policy \\ Investment Disclaimer

LEAVE A REPLY

Please enter your comment!
Please enter your name here

3,469FansLike
2,795FollowersFollow
4,235FollowersFollow

Live Bitcoin Price & Latest BTC Charts

Today's Latest Crypto News

YFI’s Andre Cronje isn’t Going Anywhere; ‘This Space Won't Get Rid of Me'

Andre Cronje, the guy behind yEarn and the popular YFI, is not leaving the cryptocurrency space any time soon, at least, “until there is...

Crypto Mom, Hester Peirce, Secures Second Term as SEC Commissioner Through 2025

The US Securities and Exchange (SEC) Commissioner Hester Peirce, aka “Crypto Mom,” has been confirmed for a second term that will last till June...

yEarn Expanding its Ecosystem to Bring in Hot DeFi Tokens into the Mix

DeFi craze continues to get hotter as the system grows. yEarn’s zero supply valueless token YFI climbed to a new high today at $5,300 and...

Bitcoin Dollar Cost Averaging From 2017 Market Peak Still Returned 61.8%

Bitcoin price remains strong, not far from hitting $12,000 yet again after the touch and go over the weekend. Interestingly, despite the fact that the...

DEX Leader Raises $11 Million in Series A Funding for Uniswap V3 Following an Explosive Month

A popular and widely used decentralized exchange (DEX) Uniswap has raised $11 million in Series A funding led by Andreessen Horowitz with additional investment...

BitcoinExchangeGuide is a hyper-active daily crypto news portal with care in cultivating the cryptocurrency culture with community contributors who help rewrite the bold future of blockchain finance. Subscribe on Google News, see the mission, authors, editorial links policy, investment disclaimer, privacy policy. Got News? Contact us, we are human too. Note: nothing here is financial advice, do your own research thoroughly.

Start Using Crypto Today