{"type":"rich","version":"1.0","author_name":"npub1sm6zhjmk5scuz294jmpkw99wwwjzetjgwp4fu4gn6utqgdz87hkqamnq7h","author_url":"https://nostr.ae/npub1sm6zhjmk5scuz294jmpkw99wwwjzetjgwp4fu4gn6utqgdz87hkqamnq7h","provider_name":"njump","provider_url":"https://nostr.ae","html":"📅 Original date posted:2014-03-08\n📝 Original message:On 03/08/2014 01:55 AM, Edmund Edgar wrote:\n\u003e On 4 March 2014 14:07, Odinn Cyberguerrilla\n\u003e \u003codinn.cyberguerrilla at riseup.net\n\u003e \u003cmailto:odinn.cyberguerrilla at riseup.net\u003e\u003e wrote:\n\u003e\n\u003e     Nothing is safe.\n\u003e\n\u003e\n\u003e This is true. To rephrase, imagine I gave you an ECC public key\n\u003e \u003ced_pub\u003e, you gave me back a public key \u003codinn_pub\u003e of your own\n\u003e devising, then I paid some money to the address resulting from\n\u003e add_pubkeys(\u003ced_pub\u003e,\u003codinn_pub\u003e) [1]. Can anyone either:\n\u003e\n\u003e a) Think of a way that Odinn could make an \u003codinn_pub\u003e such that they\n\u003e could spend the resulting money without having \u003ced_priv\u003e.\n\u003e b) Opine, somewhat knowledgeably, that this probably wouldn't be an\n\u003e easy thing to do, and they wouldn't be alarmed to see people running\n\u003e software that did this kind of thing.\n\u003e\n\u003e [1] https://github.com/vbuterin/pybitcointools/blob/master/pybitcointools/main.py#L173\n\nConsider that I see your public key \u003ca_pub\u003e before I create and send you\nmy public key \u003cb_pub\u003e.\n\nI create a new keypair, \u003cc_pub\u003e with \u003cc_priv\u003e which I know (it can be\nany arbitrary key pair).  But I don't give you \u003cc_pub\u003e, I give you \n\u003cb_pub\u003e = \u003cc_pub\u003e minus \u003ca_pub\u003e (which I can do because I've seen\n\u003ca_pub\u003e before doing this). \n\nSure, I don't know the private key for \u003cb_pub\u003e, but it doesn't matter...\nbecause what\n\n\u003cb_pub\u003e + \u003ca_pub\u003e = \u003cc_pub\u003e (mine)\n\nYou have no way to detect this condition, because you don't know what\nc_pub/c_priv I created, so you can only detect this after it's too late\n(after I abuse the private key)\n\n-Alan\n-------------- next part --------------\nAn HTML attachment was scrubbed...\nURL: \u003chttp://lists.linuxfoundation.org/pipermail/bitcoin-dev/attachments/20140308/7cfbe3a0/attachment.html\u003e"}
