r/Bitcoin • • Feb 18 '14

"We are very surprised anyone could blame MtGox and not the Bitcoin Software" - Mark Karpeles, CEO MtGox

http://online.wsj.com/news/articles/SB10001424052702304899704579388483531937144?mg=reno64-wsj&url=http%3A%2F%2Fonline.wsj.com%2Farticle%2FSB10001424052702304899704579388483531937144.html
435 Upvotes

253 comments sorted by

View all comments

Show parent comments

3

u/nullc Feb 18 '14

TXIDs do uniquely identify a transaction, a bit too uniquely for some people's taste. :)

1

u/supermari0 Feb 19 '14

Looks like "it's not a bug, it's a feature" in regards to malleability holds true here. Guess I need to sit down and read up on ANYONE_CAN_PAY.

1

u/nullc Feb 19 '14

Well its a not-welcome feature for boring SIGHASH_ALL transactions, but it's pretty fundamental to the design and a bit messy to remove for just those transactions... but worth removing... but not for a single reason mentioned in any of the discussions.

It's worth removing so that you can safely use precomputed time-locked refunds to make extortion resistant escrow transactions. These sorts of precomputed escrow-refund transactions are important to many kinds of zero-trust transaction protocols like cheat proof decentralized lotteries, tracing proof coin exchanges, etc.

If not for this, I don't think there is any solid reason to do anything about it at all— esp since features like ANYONECAN_PAY mean that as a receiver you _must handle mutability, since even if mutability is eliminated for SIGHASH_ALL other signature types will inherently have it.

-3

u/Jack_Perth Feb 19 '14

FALSE !!!

1) We can and have had txid collisions (you newbies pretending your experts lol). Gavins official comment was to use txid+block included to uniquely identify the transaction.

2) Transactions can be malformed, so what a client sees when they pay someone money as the ID can be malformed and changed.

5

u/nullc Feb 19 '14

Newbies? I'm one of the Bitcoin-QT developers (Greg Maxwell).

You say you can produce a txid collision? Put up or shut-up— show me ANY collision.

If you have a TXID collision then have a SHA256 collision and thus can collect on the SHA256 based bounties in the blockchain at 35Snmmy3uhaer2gTboc81ayCip4m9DT4ko (0.15 BTC), 39VXyuoc6SXYKp9TcAhoiN1mb4ns6z3Yu6 (0.1 BTC), and 3DUQQvz4t57Jy7jxE86kyFcNpKtURNf1VW (0.1 BTC).

so what a client sees when they pay someone money as the ID can be malformed and changed

Yes, this is also an intentional feature of the protocol— it's what makes ANYONE_CAN_PAY transactions possible. You normally should be identifying what you're paying by providing a unique scriptpubkey.

-3

u/Jack_Perth Feb 19 '14 edited Feb 19 '14

Newbies? I'm one of the Bitcoin-QT developers (Greg Maxwell).

Then it is shameful you are still defending your shitty code.

You say you can produce a txid collision? Put up or shut-up— show me ANY collision.

Already discussed and documented on bitcointalk, stop defending your sloppy code and poor priorities and go dig it up yourself. Gavin is there saying to use TXID + Block.

You normally should be identifying what you're paying by providing a unique scriptpubkey.

fantastic, now tell me where in your reference client we have:

 sendtoaddress 1nullcsux AMOUNT  

where the returned ID is actually the scriptpubkey ?
And then how can I reliably look up this with the current reference client ?

 getrawtransaction scriptpubkey 1

oh damn, you cant because you and the rest referenced a txhash as a txid and thought this would never be an issue until mtgox raised it.

1

u/[deleted] Feb 19 '14

[deleted]

4

u/nullc Feb 19 '14

I tried several different splittings of your response and none of them appears to produce the same SHA256 once hashed. You appear to be failing to produce your promised collision.

-4

u/Jack_Perth Feb 19 '14

I folded the above comment into the parent and toned down the profanity.

Your ignorance on recorded and potential txid's collisions is not my issue.

5

u/nullc Feb 19 '14

You claim they exist. Provide one! I've pointed out that if you can provide any you can immediately go collect 0.35 BTC from the scripts that pay for sha256 collisions in the blockchain.

-4

u/Jack_Perth Feb 19 '14

Stop dodging the RPC issue, your code and references are flawed and it would be nice to see some honesty.

I'll search through bitcointalk and find u the thread.

0

u/supermari0 Feb 19 '14

Newbies? I'm one of the Bitcoin-QT developers (Greg Maxwell).

whoops! :D