Re: [Lightning-dev] BOLT3: Commitment Transaction Outputs is weak to malleability

2017-11-30 Thread Rusty Russell
Nicolas Dorier writes: > I noticed the Commitment Transaction Output script is weak to malleability, > this can be used to delay confirmation of the revocation. > Luckily, fixing the situation does not require lots of development. Oh, wow! FWIW I'm a bit mindblown by

Re: [Lightning-dev] BOLT3: Commitment Transaction Outputs is weak to malleability

2017-11-28 Thread Nicolas Dorier
Actually this was merged as policy rules in 0.14, not 0.15.1. Not as bad as I thought, but still a bit uneasy about someone malleating my transaction. Another way to fix the situation which would not require the BOLT to change is to enable RBF of the Penalty transaction so Eve transaction would