Bisq Decentelized Exchange v. 1.0 Released

16 April 2019   239

The developers of Bisq presented a new version of the decentralized exchange (v1.0).

The project repository on GitHub notes that version 1.0 is the most important milestone in the development of the Bisq platform.

Thus, the new version of the software implements a decentralized autonomous organization mechanism (Bisq DAO). It allows exchange users to directly participate in project management.

For example, those who contribute to the development of Bisq may receive rewards in BSQ tokens. Also, the use of these assets can reduce trade commissions by 90%.

Among other changes - bug fixes, minor improvements to the user interface.

Matrix & Riot Hosts Shut Down Due to Hack

Matrix team says that the hacking was done through a vulnerability in an un-upgraded Jenkins continuous integration system
12 April 2019   311

The developers of the platform for decentralized messaging Matrix have announced an emergency shutdown of the servers and (the main client of the Matrix) in connection with the hacking of the project infrastructure. The first shutdown took place last night, after which the servers were restored, and the applications were reassembled from the reference source. But a few minutes ago the servers were compromised a second time.

The attackers placed on the main page of the project detailed information about the server configuration and the data on whether they have a database with hashes of almost five and a half million Matrix users. As evidence, hash password of project leader is in open access. The modified site code is placed in the repository of attackers on GitHub (not in the official matrix repository). Details about the second hack are not yet available.

After the first hacking, the Matrix team published a report stating that the hacking was done through a vulnerability in an un-upgraded Jenkins continuous integration system. After gaining access to the server with Jenkins, the attackers intercepted the SSH keys and were able to access other infrastructure servers. It was stated that the source code and packages were not affected by the attack. The attack also did not affect servers. But the attackers gained access to the main DBMS, which also contains unencrypted messages, access tokens and password hashes.

All users were adviced to change passwords. But in the process of changing passwords in the main Riot client, users are faced with the loss of files with backup copies of keys for restore encrypted correspondence and the inability to access message history.