{"type":"rich","version":"1.0","author_name":"npub1tjephawh7fdf6358jufuh5eyxwauzrjqa7qn50pglee4tayc2ntqcjtl6r","author_url":"https://nostr.ae/npub1tjephawh7fdf6358jufuh5eyxwauzrjqa7qn50pglee4tayc2ntqcjtl6r","provider_name":"njump","provider_url":"https://nostr.ae","html":"📅 Original date posted:2016-01-08\n📝 Original message:On Fri, Jan 8, 2016 at 2:54 AM, Gavin Andresen via bitcoin-dev \u003c\nbitcoin-dev at lists.linuxfoundation.org\u003e wrote:\n\u003e I'm saying we can eliminate one somewhat unlikely attack (that there is a\n\u003e bug in the code or test cases, today or some future version, that has to\n\u003e decide what to do with \"version 0\" versus \"version 1\" witness programs) by\n\u003e accepting the risk of another insanely, extremely unlikely attack.\n\nOk, just having one witness program version now is a somewhat different\nproposal. It would be simpler for sure. The reasoning was that you'd need\nthis to not add significant overhead to small scripts, but that may not be\nthe case anymore. I wouldn't mind seeing numbers.\n\n\u003e My proposal would be to just do a version 0 witness program now, that is\n\u003e RIPEMD160(SHA256(script)).\n\nI don't think that is wise. Bitcoin has a 128-bit security target for\neverything else. We did not know that P2SH and similar constructs were\nvulnerable to a collision attack at the time, but now we do, so the obvious\nchoice is to pick a size that is sufficiently large to maintain the 128-bit\nsecurity target. This is a no brainer to me; we're not proposing switching\nto a 160-bit EC curve either, right?\n\n\u003e I'm really disappointed with the \"Here's the spec, take it or leave it\"\n\u003e attitude. What's the point of having a BIP process if the discussion just\n\u003e comes down to \"We think more is better. We don't care what you think.\"\n\nIt is a proposal and we are discussing it. You first brought up some\ncriticisms in private, and I agreed with several things you said.\n\nBut it remains the proposal of a few people including me, and I do not\nagree with the specific suggestion of reducing the security target for\nwitness scripts to 80 bits.\n\nWe are not deciding what the system will be. We're making a proposal, and\nhope that due to its technical merit, the ecosystem will adopt it. You're\nfree to participate in that discussion.\n\n-- \nPieter\n-------------- next part --------------\nAn HTML attachment was scrubbed...\nURL: \u003chttp://lists.linuxfoundation.org/pipermail/bitcoin-dev/attachments/20160108/2420393c/attachment.html\u003e"}
