{"type":"rich","version":"1.0","author_name":"npub1s4lj77xuzcu7wy04afcr487f0r3za0f8n2775xrpkld2sv639mjqsd44kw","author_url":"https://nostr.ae/npub1s4lj77xuzcu7wy04afcr487f0r3za0f8n2775xrpkld2sv639mjqsd44kw","provider_name":"njump","provider_url":"https://nostr.ae","html":"📅 Original date posted:2016-01-07\n📝 Original message:Maybe I'm asking this question on the wrong mailing list:\n\nMatt/Adam: do you have some reason to think that RIPEMD160 will be broken\nbefore SHA256?\nAnd do you have some reason to think that they will be so broken that the\nnested hash construction RIPEMD160(SHA256()) will be vulnerable?\n\nAdam: re: \"where to stop\"  :  I'm suggesting we stop exactly at the current\nstatus quo, where we use RIPEMD160 for P2SH and P2PKH.\n\nEthan:  your algorithm will find two arbitrary values that collide. That\nisn't useful as an attack in the context we're talking about here (both of\nthose values will be useless as coin destinations with overwhelming\nprobability).\n\nDave: you described a first preimage attack, which is 2**160 cpu time and\nno storage.\n\n\n-- \n--\nGavin Andresen\n-------------- next part --------------\nAn HTML attachment was scrubbed...\nURL: \u003chttp://lists.linuxfoundation.org/pipermail/bitcoin-dev/attachments/20160107/a777b3e1/attachment.html\u003e"}
