bitcoinerrorlog on Nostr: We did not include signing all data for a reason. It doesn't actually fix anything. ...
We did not include signing all data for a reason. It doesn't actually fix anything.
Some of the problems people quote to justify signing everything are only theoretical problems (you never hear about trusted servers mutating data really,, despite it being possible). And all of the problems signing introduces are ignored.
If you want attestation or proofs there are better ways to do it either incidentally or inherently with tree structures.
I'd rather have a mirror/watchtower than a bunch of floating signed messages inconsistently available across relays.
Some of the problems people quote to justify signing everything are only theoretical problems (you never hear about trusted servers mutating data really,, despite it being possible). And all of the problems signing introduces are ignored.
If you want attestation or proofs there are better ways to do it either incidentally or inherently with tree structures.
I'd rather have a mirror/watchtower than a bunch of floating signed messages inconsistently available across relays.