<oembed><type>rich</type><version>1.0</version><author_name>npub1s4lj77xuzcu7wy04afcr487f0r3za0f8n2775xrpkld2sv639mjqsd44kw</author_name><author_url>https://nostr.ae/npub1s4lj77xuzcu7wy04afcr487f0r3za0f8n2775xrpkld2sv639mjqsd44kw</author_url><provider_name>njump</provider_name><provider_url>https://nostr.ae</provider_url><html>📅 Original date posted:2016-01-07&#xA;📝 Original message:On Thu, Jan 7, 2016 at 8:26 PM, Matt Corallo &lt;lf-lists at mattcorallo.com&gt;&#xA;wrote:&#xA;&#xA;&gt; So just because other attacks are possible we should weaken the crypto&#xA;&gt; we use? You may feel comfortable weakening crypto used to protect a few&#xA;&gt; billion dollars of other peoples&#39; money, but I dont.&#xA;&gt;&#xA;&#xA;No...&#xA;&#xA;I&#39;m saying we can eliminate one somewhat unlikely attack (that there is a&#xA;bug in the code or test cases, today or some future version, that has to&#xA;decide what to do with &#34;version 0&#34; versus &#34;version 1&#34; witness programs) by&#xA;accepting the risk of another insanely, extremely unlikely attack.&#xA;&#xA;Reference for those who are lost:&#xA;&#xA;https://github.com/CodeShark/bips/blob/segwit/bip-codeshark-jl2012-segwit.mediawiki#witness-program&#xA;&#xA;My proposal would be to just do a version 0 witness program now, that is&#xA;RIPEMD160(SHA256(script)).&#xA;&#xA;And ten or twenty years from now, if there is a plausible attack on&#xA;RIPEMD160 and/or SHA256, revisit and do a version 11 (or whatever).&#xA;&#xA;It will simplify the BIP, means half as many test cases have to be written,&#xA;means a little more scalability, and is as secure as the P2SH and P2PKH&#xA;everybody is using to secure their bitcoin today.&#xA;&#xA;Tell you what:  I&#39;ll change my mind if anybody can describe a plausible&#xA;attack if we were using MD5(SHA256), given what we know about how MD5 is&#xA;broken.&#xA;&#xA;&#xA;---&#xA;&#xA;I&#39;m really disappointed with the &#34;Here&#39;s the spec, take it or leave it&#34;&#xA;attitude. What&#39;s the point of having a BIP process if the discussion just&#xA;comes down to &#34;We think more is better. We don&#39;t care what you think.&#34;&#xA;&#xA;-- &#xA;--&#xA;Gavin Andresen&#xA;-------------- next part --------------&#xA;An HTML attachment was scrubbed...&#xA;URL: &lt;http://lists.linuxfoundation.org/pipermail/bitcoin-dev/attachments/20160107/ba55bae0/attachment.html&gt;</html></oembed>