4 ms·
Well, the signature itself can't be signed (obviously). But that's not a problem for many other uses of cryptographic signatures, there's something about the Bi
by codeflo 13y ago
Well, the signature itself can't be signed (obviously). But that's not a problem for many other uses of cryptographic signatures, there's something about the Bitcoin protocol that makes this an issue, and I'm trying to understand what that is.
Why is there any choice in how the signature is encoded? Why is there some sort of "script" (I'm not sure I understand this part) that's important enough to be hashed, but not important enough to be signed? This looks like a very deliberate design decision.
- gus_massa 13y agoI can’t find the exact quote or reference now, but IIRC it was possible to sign a .Net assembly or script, and the signature was in a special block that said “Please ignore this block to calculate the signature”. So you can create the whole thing, calculate the signature and put it in the correct slot without changing the signature.
- oillio 13y agoThis is effectively how bitcoin transactions work now. It gets considerably more complicated when you include multi-party signatures. In this case, transactions are signed by multiple private keys, but none of the parties will know the other signatures before they sign the transaction themselves.
- deleted 13y ago[deleted]
- oillio 13y agoDue to the intricacies of ECC (the cryptography used in signing transactions) the signature can always be mutated to produce a different, but equally valid signature. If the developers want to avoid transaction malleability, they will not be able to include the signature in the hash.
- Anderkent 13y ago> If the developers want to avoid transaction malleability, they will not be able to include the signature in the hash. Would that be a problem? Since a transaction is already uniquely identified by the inputs, why not hash everything that's signed and use that as the identifier in (tx, index) pair?