<oembed><type>rich</type><version>1.0</version><author_name>npub108dfgewsuqzm6cvllzmxsv0xnn69rrjnyg5pa32a727k89ndh3xqmsr4hp</author_name><author_url>https://nostr.ae/npub108dfgewsuqzm6cvllzmxsv0xnn69rrjnyg5pa32a727k89ndh3xqmsr4hp</author_url><provider_name>njump</provider_name><provider_url>https://nostr.ae</provider_url><html>📅 Original date posted:2016-01-07&#xA;📝 Original message:On Jan 7, 2016 5:22 PM, &#34;Gavin Andresen via bitcoin-dev&#34; &lt;&#xA;bitcoin-dev at lists.linuxfoundation.org&gt; wrote:&#xA;&gt;&#xA;&gt; On Thu, Jan 7, 2016 at 6:52 PM, Pieter Wuille &lt;pieter.wuille at gmail.com&gt;&#xA;wrote:&#xA;&gt;&gt;&#xA;&gt;&gt; Bitcoin does have parts that rely on economic arguments for security or&#xA;privacy, but can we please stick to using cryptography that is up to par&#xA;for parts where we can? It&#39;s a small constant factor of data, and it&#xA;categorically removes the worry about security levels.&#xA;&gt;&#xA;&gt; Our message may have crossed in the mod queue:&#xA;&gt;&#xA;&gt; &#34;So can we quantify the incremental increase in security of&#xA;SHA256(SHA256) over RIPEMD160(SHA256) versus the incremental increase in&#xA;security of having a simpler implementation of segwitness?&#34;&#xA;&#xA;There are several clever ways to exploit even chosen prefix collisions&#xA;using the scripting language. One could search for collisions where one&#xA;message is some data and the other is a jump over a critical check.&#xA;&#xA;&gt;&#xA;&gt; I believe the history of computer security is that implementation errors&#xA;and sidechannel attacks are much, much more common than brute-force breaks.&#xA;KEEP IT SIMPLE.&#xA;&#xA;Ask the Iranian nuclear program. Or those brainwallet users.&#xA;&gt;&#xA;&gt; (and a quibble:  &#34;do a 80-bit search for B and C such that H(A and B) =&#xA;H(B and C)&#34;  isn&#39;t enough, you have to end up with a C public key for which&#xA;you know the corresponding private key or the attacker just succeeds in&#xA;burning the funds)&#xA;&gt;&#xA;&gt;&#xA;&gt; --&#xA;&gt; --&#xA;&gt; Gavin Andresen&#xA;&gt;&#xA;&gt; _______________________________________________&#xA;&gt; bitcoin-dev mailing list&#xA;&gt; bitcoin-dev at lists.linuxfoundation.org&#xA;&gt; https://lists.linuxfoundation.org/mailman/listinfo/bitcoin-dev&#xA;&gt;&#xA;-------------- next part --------------&#xA;An HTML attachment was scrubbed...&#xA;URL: &lt;http://lists.linuxfoundation.org/pipermail/bitcoin-dev/attachments/20160107/9bdcb94f/attachment-0001.html&gt;</html></oembed>