logoalt Hacker News

woodruffwtoday at 4:42 AM0 repliesview on HN

As far as compact encodings go, this kind of patch-and-fill technique isn't particularly egregious. The alternative mentioned (where the verifier has to be aware of a bitfield that defines the to-be-signed elements) is much easier to mess up!