{"type":"rich","version":"1.0","author_name":"npub1axv7m5dyyrnatcvmu7rse0860x9mnr95prje9x32rqvperr0rhhqp0ftr0","author_url":"https://nostr.ae/npub1axv7m5dyyrnatcvmu7rse0860x9mnr95prje9x32rqvperr0rhhqp0ftr0","provider_name":"njump","provider_url":"https://nostr.ae","html":"📅 Original date posted:2019-07-09\n📝 Original message:Hi all,\n\nJust to be brief, I'll kick off with an attack scenario.\n\n1. I am a signer, I get a PSBT that is ready to sign. I parse. I sign\naccording to the PSBT as-is.\n2. I notice my UTXO was stolen by a hacker because they changed my PSBT\ninput's sighashtype to SIGHASH_ANYONECANPAY | SIGHASH_NONE and after the\nfact they changed the outputs to send to themselves, and added an input\nthey signed with SIGHASH_ALL.\n3. I lose the BTC in my UTXO.\n\nSo we should definitely add to the signer checks \"ensure the sighash type\ngiven is the type of sighash you want to sign.\" etc.\n\nMy proposal for a wording change would be addition to the bullet list:\n\n- If a sighash type is provided, the signer MUST check that the sighash\ntype is acceptable to them, and fail signing if unacceptable.\n- If a sighash type is not provided, the signer SHOULD sign using\nSIGHASH_ALL, but may sign with any sighash type they wish.\n\nAny thoughts?\n\nThanks,\nJon\n\n-- \n-----------------\nJonathan Underwood\nビットバンク社 チーフビットコインオフィサー\n-----------------\n\n暗号化したメッセージをお送りの方は下記の公開鍵をご利用下さい。\n\n指紋: 0xCE5EA9476DE7D3E45EBC3FDAD998682F3590FEA3\n-------------- next part --------------\nAn HTML attachment was scrubbed...\nURL: \u003chttp://lists.linuxfoundation.org/pipermail/bitcoin-dev/attachments/20190710/60601766/attachment.html\u003e"}
