Discussion on BIP 322 Enhancements and Issues

20 replies 121 views
0xNodeMember
Posts: 671 · Reputation: 80
#1Nov 8, 2020, 05:47 AM
Here we go with the discussion on BIP322 improvements and stuff that needs sorting out in the draft. There’s a GitHub issue where folks are pointing out problems and trying to refine it all. Let's pitch in and help out.
3 Reply Quote Share
0xNodeMember
Posts: 671 · Reputation: 80
#2Nov 8, 2020, 07:15 AM
The GitHub issue is a key place for everyone to weigh in on BIP322. It's interesting how many opinions are flying around.
2 Reply Quote Share
diamondhandsHero Member
Posts: 200 · Reputation: 2112
#3Nov 8, 2020, 10:10 AM
One thing is for sure, though if we don’t get some decent standalone script interpreters, BIP322 isn't gonna see wide use anytime soon.
2 Reply Quote Share
0xNodeMember
Posts: 671 · Reputation: 80
#4Nov 8, 2020, 03:05 PM
You can totally make it easier. Just change the signed message for each address type. Define it like "<constant><addressData><constant>", hash it all, and that’s pretty much it. Other parts stay the same and you can keep the format BIP-322 compatible.
1 Reply Quote Share
diamondhandsHero Member
Posts: 200 · Reputation: 2112
#5Nov 8, 2020, 05:35 PM
@garlonicon: This isn’t about me anymore. It's about simplifying BIP322 for everyone. Are we really only hashing the transaction for signing? I don’t see any cryptographic checks happening in the verification. Like, ECDSA does more... What gives?
2 Reply Quote Share
mr_apeNewbie
Posts: 401 · Reputation: 35
#6Nov 8, 2020, 09:58 PM
What's this "proof of sent-transaction" nonsense? You can just make a structure and sign it. Figuring out if it connects to actual coins? That's on the recipient. And there’s always the simple pubkey verification.
0 Reply Quote Share
matrix2021Full Member
Posts: 92 · Reputation: 612
#7Nov 8, 2020, 11:25 PM
Not gonna lie, that’s impossible because BIP322 needs a ton of script code that most tools just don’t have. Like, look at Electrum it barely deals with scripts. Adding a script interpreter isn’t in the cards.
6 Reply Quote Share
diamondhandsHero Member
Posts: 200 · Reputation: 2112
#8Nov 9, 2020, 05:17 AM
Nah, you're twisted there. BIP 322 is signing a fake transaction but with a signature that’s not really cryptographic. It’s more about the whole script execution to see if a signature is valid or not.
3 Reply Quote Share
basedblockFull Member
Posts: 5 · Reputation: 693
#9Nov 9, 2020, 05:25 AM
We might have to take baby steps, though. Just get P2PKH validation sorted for BIP-322. That's pretty much a matter of address handling and some constants. Easy!
1 Reply Quote Share
mr_apeNewbie
Posts: 401 · Reputation: 35
#10Nov 9, 2020, 05:34 AM
So, @OP, Greg Maxwell mentioned something on GitHub: this isn’t correct. There’s no digital signature scheme being proposed. This ‘sign by script’ is claiming some sort of superiority which is questionable.
1 Reply Quote Share
diamondhandsHero Member
Posts: 200 · Reputation: 2112
#11Nov 9, 2020, 07:02 AM
But if we stick to your idea, we’ll just end up back at BIP137, which most wallets already understand. Your idea sounds like it needs hardcoded values, which isn’t clean code and it’ll fail scalability.
1 Reply Quote Share
0xNodeMember
Posts: 671 · Reputation: 80
#12Nov 10, 2020, 09:32 AM
To get backward compatibility, OP_CHECKDATASIG is a solid choice. But we could just stick to <signature> <pubkey> OP_CHECKSIG, assuming it checks against a Bitcoin Message.
1 Reply Quote Share
diamondhandsHero Member
Posts: 200 · Reputation: 2112
#13Nov 11, 2020, 09:16 AM
I finally got it we need two transactions. One to create coins and the other to spend them. Gotta keep future expansions in mind.
2 Reply Quote Share
0xNodeMember
Posts: 671 · Reputation: 80
#14Nov 11, 2020, 10:42 AM
So transaction-based signing is powerful but complex. A lot of users just want something simple to sign messages. Like, why didn’t Legacy add BIP137 signatures, makes no sense.
5 Reply Quote Share
diamondhandsHero Member
Posts: 200 · Reputation: 2112
#15Nov 11, 2020, 04:12 PM
I think it’s just the scriptSig we’re talking about. You can create a full signed transaction from the data you’ve got. Changing the transaction version would break BIP-322.
3 Reply Quote Share
0xNodeMember
Posts: 671 · Reputation: 80
#16Nov 12, 2020, 07:48 AM
Best way? Start small with a BIP322 signing and checking program first. Build a full script interpreter later. It’s still a draft after all.
2 Reply Quote Share
basedblockFull Member
Posts: 5 · Reputation: 693
#17Nov 14, 2020, 07:07 AM
I swear this makes no sense. Who thought this was a good idea? The latest BIP322 drafts say it ties a fake txn to its witness data, which is pointless without some real verification.
4 Reply Quote Share
matrix2021Full Member
Posts: 92 · Reputation: 612
#18Nov 14, 2020, 01:22 PM
Actually, quite a few people brought it up. And it’s not trolling, it could actually help. It’s not a twin implementation, it’s using the existing script interpreter from Bitcoin.
0 Reply Quote Share
diamondhandsHero Member
Posts: 200 · Reputation: 2112
#19Nov 15, 2020, 01:01 PM
Then you can track down the author of BIP-322: Karl-Johan Alm. You could skip BIP-322 and focus on the Bitcoin Message instead. But guess what? It has limits, especially with non-P2PKH addresses.
0 Reply Quote Share
basedblockFull Member
Posts: 5 · Reputation: 693
#20Nov 15, 2020, 03:13 PM
That applies only to Bitcoin Core. What about third party wallets? They might never get it right. Tying transactions to signatures is new and it’s a feature that opens up possibilities.
4 Reply Quote Share

Related topics