<oembed><type>rich</type><version>1.0</version><author_name>npub1zw7cc8z78v6s3grujfvcv3ckpvg6kr0w7nz9yzvwyglyg0qu5sjsqhkhpx</author_name><author_url>https://nostr.ae/npub1zw7cc8z78v6s3grujfvcv3ckpvg6kr0w7nz9yzvwyglyg0qu5sjsqhkhpx</author_url><provider_name>njump</provider_name><provider_url>https://nostr.ae</provider_url><html>📅 Original date posted:2016-01-08&#xA;📝 Original message:Matt Corallo &lt;lf-lists at mattcorallo.com&gt; writes:&#xA;&gt; Indeed, anything which uses P2SH is obviously vulnerable if there is&#xA;&gt; an attack on RIPEMD160 which reduces it&#39;s security only marginally.&#xA;&#xA;I don&#39;t think this is true?  Even if you can generate a collision in&#xA;RIPEMD160, that doesn&#39;t help you since you need to create a specific&#xA;SHA256 hash for the RIPEMD160 preimage.&#xA;&#xA;Even a preimage attack only helps if it leads to more than one preimage&#xA;fairly cheaply; that would make grinding out the SHA256 preimage easier.&#xA;AFAICT even MD4 isn&#39;t this broken.&#xA;&#xA;But just with Moore&#39;s law (doubling every 18 months), we&#39;ll worry about&#xA;economically viable attacks in 20 years.[1]&#xA;&#xA;That&#39;s far enough away that I would choose simplicity, and have all SW&#xA;scriptPubKeys simply be &#34;&lt;0&gt; RIPEMD(SHA256(WP))&#34; for now, but it&#39;s&#xA;not a no-brainer.&#xA;&#xA;Cheers,&#xA;Rusty.&#xA;&#xA;[1] Assume bitcoin-network-level compute (collision in 19 days) costs&#xA;    $1B to build today.  Assume there will be 100 million dollars a day&#xA;    in vulnerable txs, and you&#39;re on one end of all of them (or can MITM&#xA;    if you find a collision), *and* can delay them all by 10 seconds,&#xA;    and none are in parallel so you can attack all of them.  IOW, just&#xA;    like a single $100M opportunity for 3650 seconds each year.&#xA;&#xA;    Our machine has a 0.11% chance of finding a collision in 1 hour, so&#xA;    it&#39;s worth about $110,000.  We can build it for that in about 20&#xA;    years.</html></oembed>