<oembed><type>rich</type><version>1.0</version><author_name>npub1e46n428mcyfwznl7nlsf6d3s7rhlwm9x3cmkuqzt3emmdpadmkaqqjxmcu</author_name><author_url>https://nostr.ae/npub1e46n428mcyfwznl7nlsf6d3s7rhlwm9x3cmkuqzt3emmdpadmkaqqjxmcu</author_url><provider_name>njump</provider_name><provider_url>https://nostr.ae</provider_url><html>📅 Original date posted:2016-01-08&#xA;📝 Original message:Indeed, anything which uses P2SH is obviously vulnerable if there is an attack on RIPEMD160 which reduces it&#39;s security only marginally. While no one thought hard about these attacks when P2SH was designed, we realized later this was not such a good idea to reuse the structure from P2PKH. Hence why this discussion came up.&#xA;&#xA;On January 7, 2016 7:30:11 PM PST, Rusty Russell via bitcoin-dev &lt;bitcoin-dev at lists.linuxfoundation.org&gt; wrote:&#xA;&gt;Pieter Wuille via bitcoin-dev &lt;bitcoin-dev at lists.linuxfoundation.org&gt;&#xA;&gt;writes:&#xA;&gt;&gt; Yes, this is what I worry about. We&#39;re constructing a 2-of-2 multisig&#xA;&gt;&gt; escrow in a contract. I reveal my public key A, you do a 80-bit&#xA;&gt;search for&#xA;&gt;&gt; B and C such that H(A and B) = H(B and C). You tell me your keys B,&#xA;&gt;and I&#xA;&gt;&gt; happily send to H(A and B), which you steal with H(B and C).&#xA;&gt;&#xA;&gt;FWIW, this attack would effect the current lightning-network&#xA;&gt;&#34;deployable&#xA;&gt;lightning&#34; design at channel establishment; we reveal our pubkey in the&#xA;&gt;opening packet (which is used to redeem a P2SH using normal 2of2).&#xA;&gt;&#xA;&gt;At least you need to grind before replying (which will presumably time&#xA;&gt;out), rather than being able to do it once the channel is open.&#xA;&gt;&#xA;&gt;We could pre-commit by exchanging hashes of pubkeys first, but&#xA;&gt;contracts&#xA;&gt;on bitcoin are hard enough to get right that I&#39;m reluctant to add more&#xA;&gt;hoops.&#xA;&gt;&#xA;&gt;Cheers,&#xA;&gt;Rusty.&#xA;&gt;_______________________________________________&#xA;&gt;bitcoin-dev mailing list&#xA;&gt;bitcoin-dev at lists.linuxfoundation.org&#xA;&gt;https://lists.linuxfoundation.org/mailman/listinfo/bitcoin-dev</html></oembed>