{"type":"rich","version":"1.0","author_name":"npub1s4lj77xuzcu7wy04afcr487f0r3za0f8n2775xrpkld2sv639mjqsd44kw","author_url":"https://nostr.ae/npub1s4lj77xuzcu7wy04afcr487f0r3za0f8n2775xrpkld2sv639mjqsd44kw","provider_name":"njump","provider_url":"https://nostr.ae","html":"📅 Original date posted:2015-12-08\n📝 Original message:On Tue, Dec 8, 2015 at 6:59 PM, Gregory Maxwell \u003cgreg at xiph.org\u003e wrote:\n\n\u003e \u003e We also need to fix the O(n^2) sighash problem as an additional BIP for\n\u003e ANY\n\u003e \u003e blocksize increase.\n\u003e\n\u003e The witness data is never an input to sighash, so no, I don't agree\n\u003e that this holds for \"any\" increase.\n\u003e\n\nHere's the attack:\n\nCreate a 1-megabyte transaction, with all of it's inputs spending\nsegwitness-spending SIGHASH_ALL inputs.\n\nBecause the segwitness inputs are smaller in the block, you can fit more of\nthem into 1 megabyte. Each will hash very close to one megabyte of data.\n\nThat will be O(n^2) worse than the worst case of a 1-megabyte transaction\nwith signatures in the scriptSigs.\n\nDid I misunderstand something or miss something about the 1-mb transaction\ndata and 3-mb segwitness data proposal that would make this attack not\npossible?\n\nRE: fraud proof data being deterministic:  yes, I see, the data can be\ncomputed instead of broadcast with the block.\n\nRE: emerging consensus of Core:\n\nI think it is a huge mistake not to \"design for success\" (see\nhttp://gavinandresen.ninja/designing-for-success ).\n\nI think it is a huge mistake to pile on technical debt in\nconsensus-critical code. I think we should be working harder to make things\nsimpler, not more complex, whenever possible.\n\nAnd I think there are pretty big self-inflicted current problems because\nworries about theoretical future problems have prevented us from coming to\nconsensus on simple solutions.\n\n-- \n--\nGavin Andresen\n-------------- next part --------------\nAn HTML attachment was scrubbed...\nURL: \u003chttp://lists.linuxfoundation.org/pipermail/bitcoin-dev/attachments/20151208/58a8269d/attachment.html\u003e"}
