Skip to content

Would sharing r_preimage be a security risk? #7425

Answered by ellemouton
icebaker asked this question in Q&A
Discussion options

You must be logged in to vote

Hi @icebaker,

Yes, sharing r_preimage is not a good idea. In LN world, being able to show an invoice (with the hash) along with the pre-image (which hashes to that hash) is taken as proof-of-payment.

With regards to other parts of the Invoice - none of the other parts are as big of a risk per-say since you are in any case putting most of those fields in an invoice that you will share with the person trying to pay you. But you dont necessarily want to share a single invoice with the world since something like payment_addr should really only ever be seen by the person trying to pay you. Further more, if you have some unannounced ("private") channels, then those will be in the invoice hop-hi…

Replies: 2 comments 4 replies

Comment options

You must be logged in to vote
0 replies
Answer selected by icebaker
Comment options

You must be logged in to vote
4 replies
@ellemouton
Comment options

@icebaker
Comment options

@ellemouton
Comment options

@icebaker
Comment options

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
2 participants