<oembed><type>rich</type><version>1.0</version><author_name>npub1cmt6gqyfw3sdngkq0wadtpe3kmgyyeld6ad0g2h5tar3kpzcrmpqddwkls</author_name><author_url>https://nostr.ae/npub1cmt6gqyfw3sdngkq0wadtpe3kmgyyeld6ad0g2h5tar3kpzcrmpqddwkls</author_url><provider_name>njump</provider_name><provider_url>https://nostr.ae</provider_url><html>📅 Original date posted:2017-02-24&#xA;📝 Original message:On Fri, 2017-02-24 at 16:18 +0100, Aymeric Vitte via bitcoin-dev wrote:&#xA;&gt; Not sure that you really read deeply what I sent, because stating&#xA;&gt; that&#xA;&gt; hashing files continuously instead of hashing the intermediate steps&#xA;&gt; just gives more latitude to the attacker can&#39;t be true when the&#xA;&gt; attacker&#xA;&gt; has absolutely no control over the past files&#xA;What prevents the attacker to provide different past files when talking&#xA;to parties who are still in the initial state?&#xA;&#xA;Then the question is: knowing the hash state, is it as easy to find a&#xA;&gt; collision between two files that will be computed in the next round&#xA;&gt; than&#xA;&gt; finding a collision between two files only?&#xA;With the original usage of the hash function, the hash state is always&#xA;the initial state. Now that the attacker has some control over the hash&#xA;state even. In other words, if the original use of the hash function&#xA;was vulnerable, then your scheme is vulnerable for the initial state.&#xA;&#xA;Concrete attack: If you can find x != y with H(x) = H(y), then you can&#xA;also find m, x != y, with H(m||x) = H(m||y), just by setting m = &#34;&#34;. &#xA;&#xA;Not sure if this is the right place to discuss that issue though...&#xA;&#xA;Best,&#xA;Tim</html></oembed>