3 ms·
See, that's the misconception most people have. What if an API tells you that you have an unspent output worth 0.01 BTC. and you spend it based on this informat
by 0x83F1 12y ago
See, that's the misconception most people have. What if an API tells you that you have an unspent output worth 0.01 BTC. and you spend it based on this information. If the API lied you could have just spent a 500 BTC output straight to fees with no recourse. If you just know the transaction hash and vout index you have no idea if the value is correct, many wallets reply on faulty information like this with potentially disastrous consequences.
- wslh 12y agoDo you mean something like this http://blog.coinspect.co/copay-wallet-emptying-vulnerability http://blog.coinspect.co/copay-wallet-emptying-vulnerability
- 0x83F1 12y agoNo. In a Bitcoin transaction the fees are implies by in minus out. There's no way of knowing without a proof the value of a particular output, so if you accidentally spend one far below it's actual value you can end up paying an insane fee. People have lost hundred of Bitcoin due to bugs like this, like off by one errors. A malicious or misbehaving API could misstate the value and cause you to unknowingly lose money in this way if you blindly trust them.
- soroushjp 12y agoThat's fair 0x83F1, that would be a valid attack. The economic incentive for that attack is pretty low (unless Chain is working with miners to boost their fees), but I see your point, you are definitely giving up some level of security and the trustless nature of Bitcoin by using an API for sure. I do think as the Bitcoin ecosystem grows, it's going to be inevitable that some tradeoffs are made for usability, convenience and extensibility by mainstream users. I would be most worried about any tradeoff that was both a) open to a technical attack vector b) created economic incentives for parties to be malicious. Situations with only a) or b) but not both will likely be tolerated by users and only reinvented when major issues arise.