3 ms·
This post explains the how very well. Now I wonder about the why. Why is there extra data that's part of the transaction hash, but not part of the cryptographi
by codeflo 13y ago
This post explains the how very well. Now I wonder about the why.
Why is there extra data that's part of the transaction hash, but not part of the cryptographic signature? (This fact seems to be the source of the problem.)
This is probably not by accident, so what does this design accomplish? Why isn't every bit of the transaction signed?
- nullc 13y agoAll of the transaction except the "signature"s is signed. The modifications come from modifying the signatures and/or their encoding.
- codeflo 13y agoWell, the signature itself can't be signed (obviously). But that's not a problem for many other uses of cryptographic signatures, there's something about the Bitcoin protocol that makes this an issue, and I'm trying to understand what that is. Why is there any choice in how the signature is encoded? Why is there some sort of "script" (I'm not sure I understand this part) that's important enough to be hashed, but not important enough to be signed? This looks like a very deliberate design decision.
- gus_massa 13y agoI can’t find the exact quote or reference now, but IIRC it was possible to sign a .Net assembly or script, and the signature was in a special block that said “Please ignore this block to calculate the signature”. So you can create the whole thing, calculate the signature and put it in the correct slot without changing the signature.
- oillio 13y agoThis is effectively how bitcoin transactions work now. It gets considerably more complicated when you include multi-party signatures. In this case, transactions are signed by multiple private keys, but none of the parties will know the other signatures before they sign the transaction themselves.
- deleted 13y ago[deleted]
- oillio 13y agoDue to the intricacies of ECC (the cryptography used in signing transactions) the signature can always be mutated to produce a different, but equally valid signature. If the developers want to avoid transaction malleability, they will not be able to include the signature in the hash.
- Anderkent 13y ago> If the developers want to avoid transaction malleability, they will not be able to include the signature in the hash. Would that be a problem? Since a transaction is already uniquely identified by the inputs, why not hash everything that's signed and use that as the identifier in (tx, index) pair?
- joeyh 13y agoWhy is the signature fed through a bitcoin script? Not using a (non-turing-complete-but-still) programming language to encode a signature seems like a good first step to avoiding malleability. Bitcoin has good/interesting reasons for using scripts inside transactions, but AIUI these are separate from the signature script.