<oembed><type>rich</type><version>1.0</version><author_name>npub1axv7m5dyyrnatcvmu7rse0860x9mnr95prje9x32rqvperr0rhhqp0ftr0</author_name><author_url>https://nostr.ae/npub1axv7m5dyyrnatcvmu7rse0860x9mnr95prje9x32rqvperr0rhhqp0ftr0</author_url><provider_name>njump</provider_name><provider_url>https://nostr.ae</provider_url><html>📅 Original date posted:2019-07-09&#xA;📝 Original message:Hi all,&#xA;&#xA;Just to be brief, I&#39;ll kick off with an attack scenario.&#xA;&#xA;1. I am a signer, I get a PSBT that is ready to sign. I parse. I sign&#xA;according to the PSBT as-is.&#xA;2. I notice my UTXO was stolen by a hacker because they changed my PSBT&#xA;input&#39;s sighashtype to SIGHASH_ANYONECANPAY | SIGHASH_NONE and after the&#xA;fact they changed the outputs to send to themselves, and added an input&#xA;they signed with SIGHASH_ALL.&#xA;3. I lose the BTC in my UTXO.&#xA;&#xA;So we should definitely add to the signer checks &#34;ensure the sighash type&#xA;given is the type of sighash you want to sign.&#34; etc.&#xA;&#xA;My proposal for a wording change would be addition to the bullet list:&#xA;&#xA;- If a sighash type is provided, the signer MUST check that the sighash&#xA;type is acceptable to them, and fail signing if unacceptable.&#xA;- If a sighash type is not provided, the signer SHOULD sign using&#xA;SIGHASH_ALL, but may sign with any sighash type they wish.&#xA;&#xA;Any thoughts?&#xA;&#xA;Thanks,&#xA;Jon&#xA;&#xA;-- &#xA;-----------------&#xA;Jonathan Underwood&#xA;ビットバンク社 チーフビットコインオフィサー&#xA;-----------------&#xA;&#xA;暗号化したメッセージをお送りの方は下記の公開鍵をご利用下さい。&#xA;&#xA;指紋: 0xCE5EA9476DE7D3E45EBC3FDAD998682F3590FEA3&#xA;-------------- next part --------------&#xA;An HTML attachment was scrubbed...&#xA;URL: &lt;http://lists.linuxfoundation.org/pipermail/bitcoin-dev/attachments/20190710/60601766/attachment.html&gt;</html></oembed>