The implications of the Solana Wormhole hack on the IC

I think they used to use gitlab (before publishing ic to github) - I assume they still have it and they would probably use it;

Even if they still use GitLab internally, all of the commits on the GitHub repo are still published in real time. So IIUC anyone could see whether a bug was fixed recently, i.e. O(~days), but not yet deployed via a NNS upgrade, which is O(~weeks).

For the replica upgrades - my guess is they could bypass the NNS as it’s beta and there is no NNS enforced on-chain replica upgrade (yet);

NNS is used to manage on-chain replica upgrades. There is no mechanism to “bypass” the NNS, except for the special situation where the governance canister goes down and 2/3 of node providers must vote to upgrade that canister. The Internet Computer is a blockchain managed by a DAO, and it’s working right now!

You can see a recent replica upgrade proposal here.

1 Like