I am making an attempt to ensure I perceive the query: Why Do We Use Change Descriptors when Constructing Wallets?
Context: I work on the Bitcoin Growth Equipment, the place one among our core varieties is the Pockets
sort. It has usually required 2 descriptors (an exterior descriptor and a change (inner) descriptor). This concept is normal apply and used extensively within the business, however when urgent myself to put in writing about it in our documentation, I used to be left questioning if I actually knew why this was the case. Moreover, customers that request the Pockets be usable with just one descriptor had robust opinions about how the apply of utilizing 2 descriptors was possibly outdated and never required below sure circumstances. One person informed us that it was a mistake to double down on the interior/exterior descriptor schism, and that it was a relic of the previous of folks that use electrum wallets.
As a library maintainer, that is the kind of factor I wish to have a stable grasp on. I am additionally main our documentation efforts, and plan on together with a web page on this.
Right here is my present understanding and questions.
Benefits of utilizing 2 descriptors
- It doubtlessly permits you settle for 0-conf cash when they’re coming to alter addresses, since you will need to have been the one to provoke that transaction and won’t double-spend your self.
- Privateness when utilizing a public electrum server: in instances the place you would possibly ship an entire xpub to an electrum server, you are higher off not giving up your complete keychain however solely half? (at this level it appears trivial to reconstruct transaction historical past however nonetheless, I suppose not giving it out is healthier than doing it).
- Having only one descriptor forces you to maintain observe of addresses you’ve got given out when constructing transactions, as a result of in any other case your pockets would possibly use an exterior deal with already given out as change, and if this deal with given out to somebody finally ends up being utilized by them, you may double transactions at that deal with.
- In instances the place a pockets is recovered, change addresses can nonetheless be labeled as change.
Questions I Nonetheless Have
- Are there different pitfalls customers of single-descriptor wallets ought to pay attention to within the case the place wallets use extra personal sync instruments like personal Electrum servers and CBF, and utilizing fashionable pockets practices that by no means give out repeat addresses?
- Does the “change” keychain come into coin choice in any respect in Core? For instance, are there algos for coin choice the place realizing if a UTXO is a part of the change keychain moderately than the exterior keychain issues? In that case, how does it come into play?
- Another historic information that is good to know and consider for builders of pockets can be appreciated.
Thanks!