<oembed><type>rich</type><version>1.0</version><author_name>npub1m230cem2yh3mtdzkg32qhj73uytgkyg5ylxsu083n3tpjnajxx4qqa2np2</author_name><author_url>https://nostr.ae/npub1m230cem2yh3mtdzkg32qhj73uytgkyg5ylxsu083n3tpjnajxx4qqa2np2</author_url><provider_name>njump</provider_name><provider_url>https://nostr.ae</provider_url><html>📅 Original date posted:2019-10-05&#xA;📝 Original message:On Fri, Oct 04, 2019 at 11:40:53AM -0700, Jeremy wrote:&#xA;&gt; Interesting point.&#xA;&gt; &#xA;&gt; The script is under your control, so you should be able to ensure that you&#xA;&gt; are always using a correctly constructed midstate, e.g., something like:&#xA;&gt; &#xA;&gt; scriptPubKey: &lt;-1&gt; OP_SHA256STREAM DEPTH OP_SHA256STREAM &lt;-2&gt;&#xA;&gt; OP_SHA256STREAM&#xA;&gt; &lt;hash&gt; OP_EQUALVERIFY&#xA;&gt; &#xA;&gt; would hash all the elements on the stack and compare to a known hash.&#xA;&gt; How is that sort of thing weak to midstateattacks?&#xA;&#xA;Obviously with care you can get the computation right. But at that point what&#39;s&#xA;the actual advantage over OP_CAT?&#xA;&#xA;We&#39;re limited by the size of the script anyway; if the OP_CAT output size limit&#xA;is comparable to that for almost anything you could use SHA256STREAM on you&#xA;could just as easily use OP_CAT, followed by a single OP_SHA256.&#xA;&#xA;-- &#xA;https://petertodd.org &#39;peter&#39;[:-1]@petertodd.org&#xA;-------------- next part --------------&#xA;A non-text attachment was scrubbed...&#xA;Name: signature.asc&#xA;Type: application/pgp-signature&#xA;Size: 833 bytes&#xA;Desc: not available&#xA;URL: &lt;http://lists.linuxfoundation.org/pipermail/bitcoin-dev/attachments/20191005/213e4e81/attachment.sig&gt;</html></oembed>