BrewChain – NodeJS blockchain implementation
darrenbeck.co.uk
darrenbeck.co.uk
createHash('SHA256').update(timestamp+data+index+previousHash).
I always worry about the security impact of serializing like this.If my data was "10" and the index was "110", can I just claim the data was "101" and the index was "10" and have the blockchain assert my statement is correct?
Or in other words, can I claim to own 91 more dollars than I should?
I don't have an immediate reference, but I've seen this situation addressed in may tutorials concerning properly salting passwords.
The general rule of thumb is to not serialize and hash data this way precisely because of the risk of collision that you have outlined.
I believe that something more along the lines of
createHash('SHA256').update(timestamp).update(data).update(index).update(previousHash)
though, that isn't a complete fix.Depending upon the types of "timestamp", "data", "index", and "previousHash", the value, "timestamp+data+index+previousHash", may be interpreted as a number or a string, affecting the final hash.
Splitting it up prevents this uncertainty.
https://github.com/LiskHQ/lisk