No, they would have crashed the node, they would not have been accepted as valid. This is not a soft fork.
No, they would have crashed the node, they would not have been accepted as valid. This is not a soft fork.
A softfork is a change to the bitcoin protocol wherein only previously valid blocks/transactions are made invalid. ...
https://en.bitcoin.it/wiki/Softfork
It's not clear to me yet under what conditions a node would crash. With a single duplicate input? With dozens of duplicate inputs? Duplicate inputs spending segwit outputs?
If some duplicate inputs would have been permitted without crashing nodes then the update appears to fit the definition of soft fork.
edit: also, it appears the DoS vuln doesn't apply to pre-0.14 nodes. Either those nodes would have rejected dup-input blocks (making 0.14 a hard fork?) or the update just released could be seen as a soft fork.
If this were the case it would be a complete failure of the system, rather than a DoS.
Therefore fixing the crash is not a "soft fork* because nothing was accepted in the first place.
Yes, if it actually accepted the duplicate input, that would cause unlimited inflation, which is obviously a huge deal.
Or in other words. We got extremely lucky.
Do you have a source for where this was written up, or did you come up with this on your own?
I just want to be able to reference back to this in the future. So whenever you decide to publish, I'd love to check it out!
But I'd encourage you to do a bit more investigation.
According to Bitcoin core, there is an inflation vulnerability.
https://bitcoincore.org/en/2018/09/20/notice/
So maybe you weren't too far off from independently discovering the vulnerability yourself.
Edit: apparently you were credited in discovering the vulnerability yourself in the very discloser that I linked.
Congrats!
My comment was an early disclosure before I fully understood how sensitive the details were. Even without going into detail or providing any code it was very irresponsible of me to off hand just mention that possibility. It didn't click how sensitive things were until a bitcoin core dev confirmed it. Sorry anyone who sees this. I merely reported the exploit, David Jaenson is our genius security researcher that definitely should deserve all credit.