<oembed><type>rich</type><version>1.0</version><author_name>npub1s4lj77xuzcu7wy04afcr487f0r3za0f8n2775xrpkld2sv639mjqsd44kw</author_name><author_url>https://nostr.ae/npub1s4lj77xuzcu7wy04afcr487f0r3za0f8n2775xrpkld2sv639mjqsd44kw</author_url><provider_name>njump</provider_name><provider_url>https://nostr.ae</provider_url><html>📅 Original date posted:2015-12-08&#xA;📝 Original message:On Tue, Dec 8, 2015 at 6:59 PM, Gregory Maxwell &lt;greg at xiph.org&gt; wrote:&#xA;&#xA;&gt; &gt; We also need to fix the O(n^2) sighash problem as an additional BIP for&#xA;&gt; ANY&#xA;&gt; &gt; blocksize increase.&#xA;&gt;&#xA;&gt; The witness data is never an input to sighash, so no, I don&#39;t agree&#xA;&gt; that this holds for &#34;any&#34; increase.&#xA;&gt;&#xA;&#xA;Here&#39;s the attack:&#xA;&#xA;Create a 1-megabyte transaction, with all of it&#39;s inputs spending&#xA;segwitness-spending SIGHASH_ALL inputs.&#xA;&#xA;Because the segwitness inputs are smaller in the block, you can fit more of&#xA;them into 1 megabyte. Each will hash very close to one megabyte of data.&#xA;&#xA;That will be O(n^2) worse than the worst case of a 1-megabyte transaction&#xA;with signatures in the scriptSigs.&#xA;&#xA;Did I misunderstand something or miss something about the 1-mb transaction&#xA;data and 3-mb segwitness data proposal that would make this attack not&#xA;possible?&#xA;&#xA;RE: fraud proof data being deterministic:  yes, I see, the data can be&#xA;computed instead of broadcast with the block.&#xA;&#xA;RE: emerging consensus of Core:&#xA;&#xA;I think it is a huge mistake not to &#34;design for success&#34; (see&#xA;http://gavinandresen.ninja/designing-for-success ).&#xA;&#xA;I think it is a huge mistake to pile on technical debt in&#xA;consensus-critical code. I think we should be working harder to make things&#xA;simpler, not more complex, whenever possible.&#xA;&#xA;And I think there are pretty big self-inflicted current problems because&#xA;worries about theoretical future problems have prevented us from coming to&#xA;consensus on simple solutions.&#xA;&#xA;-- &#xA;--&#xA;Gavin Andresen&#xA;-------------- next part --------------&#xA;An HTML attachment was scrubbed...&#xA;URL: &lt;http://lists.linuxfoundation.org/pipermail/bitcoin-dev/attachments/20151208/58a8269d/attachment.html&gt;</html></oembed>