<oembed><type>rich</type><version>1.0</version><title>Dr. Hax wrote</title><author_name>Dr. Hax (npub16v…meqha)</author_name><author_url>https://yabu.me/npub16v82nr4xt62nlydtj0mtxr49r6enc5r0sl2f7cq2zwdw7q92j5gs8meqha</author_url><provider_name>njump</provider_name><provider_url>https://yabu.me</provider_url><html>I&#39;m in the market for a replacement for BTCPay.&#xA;&#xA;I want a web interface to accept donations on-chain with a unique address each time, accept LN donations, and ideally be able to take payments for an e-commerce platforms like CS-Cart.&#xA;&#xA;If it could also just BE the store, and that&#39;d be fine. Self hostable, without reliance on 3rd party servers (e.g. nostr relays) and without having to run extra services (e.g. a public nostr relay). Simple and open source. That&#39;s what I&#39;m after.&#xA;&#xA;This is not because BTCPay had a vulnerability, but because of their handling of it. They intentionally omitted that vulnerability fix from their release notes, making it look like the 2FA fix was the &#34;critical vulnerability&#34; fix.&#xA;&#xA;The people who admin servers need to be able to trust the release notes to be an honest account of what has changed. We&#39;re not going to look at every line of code that has changed. We don&#39;t have time for that. You know who does have time for that? The attackers.&#xA;&#xA;Had the authors just put a single line in the release notes that said &#34;unauthenticated attacker can get the .macaroon file for LND&#34;, I would feel like I could still trust them. Doing so would not have made it any easier for the attackers, they&#39;d still have to read the patch, just the same as they had to do without proper disclosure.&#xA;&#xA;I&#39;ve worked in infosec for 15+ years, most of that time finding 0-days. We can debate about whether the details and exploit should be released before the patch, at the same time, 30 days later or 90 days later. Reasonable people can draw different conclusions there, even when looking at the same information.&#xA;&#xA;What&#39;s not debatable is whether it&#39;s good practice to do what they did. Don&#39;t take my word for it. Ask anyone who works in the field professionally. Is it okay to say there was a critical vulnerability fixed in a release and then only list one vulnerability fix in the changelog and omit another, mire serious vulnerability that was fixed?</html></oembed>