Emergency Deployment of SegWit as a partial mitigation of CVE-2017-9230



Summary:

Cameron Garnham, in a post on the Bitcoin-Dev mailing list, stated that SegWit would be a great upgrade for Bitcoin and that it partially mitigates a serious security vulnerability known as ASICBOOST. However, around 67% of the mining hash-rate does not signal for its activation, which led Cameron to study ASICBOOST and find that it was being used by this large percentage of miners who refused to signal for SegWit's activation. This led him to call into question Andreas Antonopoulos' suggestion that Gregory Maxwell's proposal to defuse covert ASICBOOST with a SegWit-like commitment to the coinbase is a better solution. Cameron argues that SegWit is not contentious within the technical community and is a credible security vulnerability that deserves attention. He believes that using it as partial security fix for a security vulnerability should not be contentious if others agree that it is not contentious. In addition, he proposes that SegWit be used as a partial-mitigation of CVE-2017-9230 and that it should be quickly strengthened via another soft-fork that makes the inclusion of witness commits mandatory. The security trade-offs of deploying a partial-mitigation to CVE-2017-9230 quickly vs more slowly but more conservatively is under intense debate.


Updated on: 2023-06-12T01:21:16.495938+00:00