<oembed><type>rich</type><version>1.0</version><author_name>npub1r3san9v5njl6798hvauyu9ntm6r9c7u8s0t65wls58gpfdcvqp5sa48d0u</author_name><author_url>https://nostr.ae/npub1r3san9v5njl6798hvauyu9ntm6r9c7u8s0t65wls58gpfdcvqp5sa48d0u</author_url><provider_name>njump</provider_name><provider_url>https://nostr.ae</provider_url><html>📅 Original date posted:2017-09-22&#xA;📝 Original message:You generally know the witness size to within a few bytes right before signing. Why would you not? You know the size of ECDSA signatures. You can be told the size of a hash preimage by the other party. It takes some contriving to come up with a scheme where one party has variable-length signatures of their chosing&#xA;&#xA;&gt; On Sep 22, 2017, at 2:32 PM, Sergio Demian Lerner &lt;sergio.d.lerner at gmail.com&gt; wrote:&#xA;&gt; &#xA;&gt; But generally before one signs a transaction one does not know the signature size (which may be variable). One can only estimate the maximum size.</html></oembed>