Skip to content

Commit

Permalink
Additional note for HW
Browse files Browse the repository at this point in the history
  • Loading branch information
NicolasDorier committed Jun 19, 2020
1 parent 7803bf8 commit 3a16c24
Showing 1 changed file with 1 addition and 0 deletions.
1 change: 1 addition & 0 deletions bip-0078.mediawiki
Original file line number Diff line number Diff line change
Expand Up @@ -382,6 +382,7 @@ The sender's software wallet can verify that the payjoin proposal is legitimate
However, a hardware wallet can't verify that this is indeed the case. This means that the security guarantee of the hardware wallet is decreased. If the sender's software is compromised, the hardware wallet would sign two valid transactions, thus sending two payments.
Without payjoin, the maximum amount of money that could be lost by a compromised software is equal to one payment (via [[#output-substitution|payment output substitution]]).
Note that the sender can opt out payment output substitution my using the optional parameter <code>disableoutputsubstitution=true</code>.
With payjoin, the maximum amount of money that can be lost is equal to two payments.
Expand Down

0 comments on commit 3a16c24

Please sign in to comment.