|
From: | Jonathan Krebs |
Subject: | [Taler] Meaning of XORed hashes in the Exchange API |
Date: | Tue, 19 Sep 2023 13:39:02 +0200 |
User-agent: | Mozilla Thunderbird |
Hi again :)I do not understand the use of the fields denominations_sig and denominations[i].hash in the /keys response:
the wallet-core repo does not seem to use these at all, all denom pubkeys are signed individually, and as the hashes are combined with xor, this does not protect against tampering with the list. (once enough denominations exist, they can be combined linearly to achieve arbitrary hash values)
Please give me a hint about intended use or history of those, or about my misunderstanding :)
Thanks in advance, thejonny
[Prev in Thread] | Current Thread | [Next in Thread] |