<oembed><type>rich</type><version>1.0</version><author_name>npub1q86n5vtxkwerzwfqza3hwls8pl8764244464talfqy2vpj0qaz6q38qwta</author_name><author_url>https://nostr.ae/npub1q86n5vtxkwerzwfqza3hwls8pl8764244464talfqy2vpj0qaz6q38qwta</author_url><provider_name>njump</provider_name><provider_url>https://nostr.ae</provider_url><html>📅 Original date posted:2020-05-01&#xA;📝 Original message:Hi Andrew,&#xA;&#xA;If you use SIGHASH_ALL it shall sign the COutPoints of all inputs which&#xA;commit to the scriptPubKeys of the txn.&#xA;&#xA;Thus the 341 hash doesn&#39;t need to sign any additional data.&#xA;&#xA;As a metadata protocol you can provide all input transactions to check the&#xA;scriptPubKeys.&#xA;&#xA;Best,&#xA;&#xA;Jeremy&#xA;--&#xA;@JeremyRubin &lt;https://twitter.com/JeremyRubin&gt;&#xA;&#xA;&#xA;On Thu, Apr 30, 2020 at 1:22 AM Andrew Kozlik via bitcoin-dev &lt;&#xA;bitcoin-dev at lists.linuxfoundation.org&gt; wrote:&#xA;&#xA;&gt; Hi everyone,&#xA;&gt;&#xA;&gt; In the current draft of BIP-0341 [1] the signature message commits to the&#xA;&gt; scriptPubKey of the output being spent by the input. I propose that the&#xA;&gt; signature message should commit to the scriptPubKeys of *all* transaction&#xA;&gt; inputs.&#xA;&gt;&#xA;&gt; In certain applications like CoinJoin, a wallet has to deal with&#xA;&gt; transactions containing external inputs. To calculate the actual amount&#xA;&gt; that the user is spending, the wallet needs to reliably determine for each&#xA;&gt; input whether it belongs to the wallet or not. Without such a mechanism an&#xA;&gt; adversary can fool the wallet into displaying incorrect information about&#xA;&gt; the amount being spent, which can result in theft of user funds [2].&#xA;&gt;&#xA;&gt; In order to ascertain non-ownership of an input which is claimed to be&#xA;&gt; external, the wallet needs the scriptPubKey of the previous output spent by&#xA;&gt; this input. It must acquire the full transaction being spent and verify its&#xA;&gt; hash against that which is given in the outpoint. This is an obstacle in&#xA;&gt; the implementation of lightweight air-gapped wallets and hardware wallets&#xA;&gt; in general. If the signature message would commit to the scriptPubKeys of&#xA;&gt; all transaction inputs, then the wallet would only need to acquire the&#xA;&gt; scriptPubKey of the output being spent without having to acquire and verify&#xA;&gt; the hash of the entire previous transaction. If an attacker would provide&#xA;&gt; an incorrect scriptPubKey, then that would cause the wallet to generate an&#xA;&gt; invalid signature message.&#xA;&gt;&#xA;&gt; Note that committing only to the scriptPubKey of the output being spent is&#xA;&gt; insufficient for this application, because the scriptPubKeys which are&#xA;&gt; needed to ascertain non-ownership of external inputs are precisely the ones&#xA;&gt; that would not be included in any of the signature messages produced by the&#xA;&gt; wallet.&#xA;&gt;&#xA;&gt; The obvious way to implement this is to add another hash to the signature&#xA;&gt; message:&#xA;&gt; sha_scriptPubKeys (32): the SHA256 of the serialization of all&#xA;&gt; scriptPubKeys of the previous outputs spent by this transaction.&#xA;&gt;&#xA;&gt; Cheers,&#xA;&gt; Andrew Kozlik&#xA;&gt;&#xA;&gt; [1]&#xA;&gt; https://github.com/bitcoin/bips/blob/master/bip-0341.mediawiki#common-signature-message&#xA;&gt; [2]&#xA;&gt; https://lists.linuxfoundation.org/pipermail/bitcoin-dev/2017-August/014843.html&#xA;&gt; _______________________________________________&#xA;&gt; bitcoin-dev mailing list&#xA;&gt; bitcoin-dev at lists.linuxfoundation.org&#xA;&gt; https://lists.linuxfoundation.org/mailman/listinfo/bitcoin-dev&#xA;&gt;&#xA;-------------- next part --------------&#xA;An HTML attachment was scrubbed...&#xA;URL: &lt;http://lists.linuxfoundation.org/pipermail/bitcoin-dev/attachments/20200430/362a5066/attachment-0001.html&gt;</html></oembed>