<oembed><type>rich</type><version>1.0</version><author_name>npub1s4lj77xuzcu7wy04afcr487f0r3za0f8n2775xrpkld2sv639mjqsd44kw</author_name><author_url>https://nostr.ae/npub1s4lj77xuzcu7wy04afcr487f0r3za0f8n2775xrpkld2sv639mjqsd44kw</author_url><provider_name>njump</provider_name><provider_url>https://nostr.ae</provider_url><html>📅 Original date posted:2016-01-08&#xA;📝 Original message:On Fri, Jan 8, 2016 at 7:02 AM, Rusty Russell &lt;rusty at rustcorp.com.au&gt; wrote:&#xA;&#xA;&gt; Matt Corallo &lt;lf-lists at mattcorallo.com&gt; writes:&#xA;&gt; &gt; Indeed, anything which uses P2SH is obviously vulnerable if there is&#xA;&gt; &gt; an attack on RIPEMD160 which reduces it&#39;s security only marginally.&#xA;&gt;&#xA;&gt; I don&#39;t think this is true?  Even if you can generate a collision in&#xA;&gt; RIPEMD160, that doesn&#39;t help you since you need to create a specific&#xA;&gt; SHA256 hash for the RIPEMD160 preimage.&#xA;&gt;&#xA;&gt; Even a preimage attack only helps if it leads to more than one preimage&#xA;&gt; fairly cheaply; that would make grinding out the SHA256 preimage easier.&#xA;&gt; AFAICT even MD4 isn&#39;t this broken.&#xA;&gt;&#xA;&#xA;It feels like we&#39;ve gone over that before, but I can never remember where&#xA;or when. I believe consensus was that if we were using the broken MD5 in&#xA;all the places we use RIPEMD160 we&#39;d still be secure today because of&#xA;Satoshi&#39;s use of nested hash functions everywhere.&#xA;&#xA;&#xA;&gt; But just with Moore&#39;s law (doubling every 18 months), we&#39;ll worry about&#xA;&gt; economically viable attacks in 20 years.[1]&#xA;&#xA;&#xA;&gt; That&#39;s far enough away that I would choose simplicity, and have all SW&#xA;&gt; scriptPubKeys simply be &#34;&lt;0&gt; RIPEMD(SHA256(WP))&#34; for now, but it&#39;s&#xA;&gt; not a no-brainer.&#xA;&#xA;&#xA;Lets see if I&#39;ve followed the specifics of the collision attack correctly,&#xA;Ethan (or somebody) please let me know if I&#39;m missing something:&#xA;&#xA;So attacker is in the middle of establishing a payment channel with&#xA;somebody. Victim gives their public key, attacker creates the innocent&#xA;fund-locking script  &#39;2 V A 2 CHECKMULTISIG&#39; (V is victim&#39;s public key, A&#xA;is attacker&#39;s) but doesn&#39;t give it to the victim yet.&#xA;&#xA;Instead they then generate about 2^81scripts that are some form of&#xA;pay-to-attacker ....&#xA;... wait, no that doesn&#39;t work, because SHA256 is used as the inner hash&#xA;function.  They&#39;d have to generate 2^129 to find a cycle in SHA256.&#xA;&#xA;Instead, they .. what? I don&#39;t see a viable attack unless RIPEMD160 and&#xA;SHA256 (or the combination) suffers a cryptographic break.&#xA;&#xA;&#xA;-- &#xA;--&#xA;Gavin Andresen&#xA;-------------- next part --------------&#xA;An HTML attachment was scrubbed...&#xA;URL: &lt;http://lists.linuxfoundation.org/pipermail/bitcoin-dev/attachments/20160108/aec650d3/attachment.html&gt;</html></oembed>