<oembed><type>rich</type><version>1.0</version><author_name>npub1tfk373zg9dnmtvxnpnq7s2dkdgj37rwfj3yrwld7830qltmv8qps8rfq0n</author_name><author_url>https://nostr.ae/npub1tfk373zg9dnmtvxnpnq7s2dkdgj37rwfj3yrwld7830qltmv8qps8rfq0n</author_url><provider_name>njump</provider_name><provider_url>https://nostr.ae</provider_url><html>📅 Original date posted:2017-04-08&#xA;📝 Original message:I think it might be important that the mandatory commitment expire as in &#xA;Greg&#39;s proposal - when we do eventually hardfork, it will be simpler to do in &#xA;a safe manner if such a commitment in the fake &#34;old block&#34; is not required.&#xA;&#xA;I don&#39;t like your proposal because it allows ASICBoost. ASICBoost effectively &#xA;makes SHA2 semi-ASIC-resistant. ASIC-resistance raises the barrier of entry to &#xA;new mining chip manufacturers, and gives a larger advantage to the miners able &#xA;to make use of it. Instead, IMO we should fix the vulnerability exploited by &#xA;ASICBoost entirely to keep SHA2 as ASIC-friendly as possible - or change the &#xA;PoW to an algorithm that is more ASIC-friendly.&#xA;&#xA;That being said, I don&#39;t think I would oppose the proposal if it gained &#xA;notably better support than Segwit currently has (as yet another compromise), &#xA;and the above concerns were addressed (eg, Bitfury and Canaan state they can &#xA;compete using ASICBoost and the patents are licensed freely to everyone).&#xA;&#xA;Luke&#xA;&#xA;&#xA;On Saturday, April 08, 2017 12:05:16 AM Jimmy Song via bitcoin-dev wrote:&#xA;&gt; I&#39;ve gotten feedback from Adam Back that you actually don&#39;t need all 32&#xA;&gt; bits in the header for overt ASICBoost, so I&#39;m modifying my proposal. Of&#xA;&gt; the 32-bit version field, bits 16 to 23 are reserved for miners, the&#xA;&gt; witness commitment stays as defined in BIP-141 except that it&#39;s now&#xA;&gt; required. BIP9 then is modified so that bits 16 to 23 are now no longer&#xA;&gt; usable.&#xA;&gt; &#xA;&gt; On Fri, Apr 7, 2017 at 3:06 PM, Jimmy Song &lt;jaejoon at gmail.com&gt; wrote:&#xA;&gt; &gt; Hey everyone, This is an idea that I had about Segwit and Gregory&#39;s&#xA;&gt; &gt; proposal from yesterday that I wanted to run by everyone on this list.&#xA;&gt; &gt; I&#39;m not at all sure what this would mean for non-upgraded nodes on the&#xA;&gt; &gt; network and would like feedback on that. This is not a formal BIP as&#xA;&gt; &gt; it&#39;s a modification to a previously submitted one, but I&#39;m happy to&#xA;&gt; &gt; formalize it if it would help.&#xA;&gt; &gt; ----------------------------------------&#xA;&gt; &gt; MotivationOne of the interesting aspects of Gregory Maxwell’s proposal is&#xA;&gt; &gt; that it only precludes the covert version of ASICBoost. He specifically&#xA;&gt; &gt; left the overt version alone.&#xA;&gt; &gt; &#xA;&gt; &gt; Overt ASICBoost requires grinding on the version bits of the Block header&#xA;&gt; &gt; instead of the Merkle Root. This is likely more efficient than the Merkle&#xA;&gt; &gt; Root grinding (aka covert ASICBoost) and requires way less resources&#xA;&gt; &gt; (much less RAM, SHA256 calculations, no tx shuffling, etc).&#xA;&gt; &gt; &#xA;&gt; &gt; If we combine Gregory Maxwell’s proposal with BIP-141 (Segwit) and add a&#xA;&gt; &gt; slight modification, this should, in theory, make ASICBoost a lot more&#xA;&gt; &gt; useful to miners and appeal to their financial interests.&#xA;&gt; &gt; The Modification&#xA;&gt; &gt; &#xA;&gt; &gt; Currently, the version bits (currently 4 bytes, or 32 bits) in the header&#xA;&gt; &gt; are used for BIP9 signaling. We change the version bits to a nonce-space&#xA;&gt; &gt; so the miners can use it for overt ASICBoost. The 32-bits are now moved&#xA;&gt; &gt; over to the Coinbase transaction as part of the witness commitment. The&#xA;&gt; &gt; witness commitment goes from 38 bytes to 42 bytes, with the last 4 bytes&#xA;&gt; &gt; being used as the version bits in the block header previously. The&#xA;&gt; &gt; witness commitment becomes required as per Gregory Maxwell’s proposal.&#xA;&gt; &gt; Reasoning&#xA;&gt; &gt; &#xA;&gt; &gt; First, this brings ASICBoost out into the open. Covert ASICBoost becomes&#xA;&gt; &gt; much more costly and overt ASICBoost is now encouraged.&#xA;&gt; &gt; &#xA;&gt; &gt; Second, we can make this change relatively quickly. Most of the Segwit&#xA;&gt; &gt; testing stays valid and this change can be deployed relatively quickly.&#xA;&gt; &gt; &#xA;&gt; &gt; Note on SPV clients&#xA;&gt; &gt; &#xA;&gt; &gt; Currently Segwit stores the witness commitment in the Coinbase tx, so&#xA;&gt; &gt; lightweight clients will need to get the Coinbase tx + Merkle proof to&#xA;&gt; &gt; validate segwit transactions anyway. Putting block version information in&#xA;&gt; &gt; the Coinbase tx will not impose an extra burden on upgraded light&#xA;&gt; &gt; clients.</html></oembed>