<oembed><type>rich</type><version>1.0</version><author_name>npub1tjephawh7fdf6358jufuh5eyxwauzrjqa7qn50pglee4tayc2ntqcjtl6r</author_name><author_url>https://nostr.ae/npub1tjephawh7fdf6358jufuh5eyxwauzrjqa7qn50pglee4tayc2ntqcjtl6r</author_url><provider_name>njump</provider_name><provider_url>https://nostr.ae</provider_url><html>📅 Original date posted:2016-01-08&#xA;📝 Original message:On Fri, Jan 8, 2016 at 2:54 AM, Gavin Andresen via bitcoin-dev &lt;&#xA;bitcoin-dev at lists.linuxfoundation.org&gt; wrote:&#xA;&gt; I&#39;m saying we can eliminate one somewhat unlikely attack (that there is a&#xA;&gt; bug in the code or test cases, today or some future version, that has to&#xA;&gt; decide what to do with &#34;version 0&#34; versus &#34;version 1&#34; witness programs) by&#xA;&gt; accepting the risk of another insanely, extremely unlikely attack.&#xA;&#xA;Ok, just having one witness program version now is a somewhat different&#xA;proposal. It would be simpler for sure. The reasoning was that you&#39;d need&#xA;this to not add significant overhead to small scripts, but that may not be&#xA;the case anymore. I wouldn&#39;t mind seeing numbers.&#xA;&#xA;&gt; My proposal would be to just do a version 0 witness program now, that is&#xA;&gt; RIPEMD160(SHA256(script)).&#xA;&#xA;I don&#39;t think that is wise. Bitcoin has a 128-bit security target for&#xA;everything else. We did not know that P2SH and similar constructs were&#xA;vulnerable to a collision attack at the time, but now we do, so the obvious&#xA;choice is to pick a size that is sufficiently large to maintain the 128-bit&#xA;security target. This is a no brainer to me; we&#39;re not proposing switching&#xA;to a 160-bit EC curve either, right?&#xA;&#xA;&gt; I&#39;m really disappointed with the &#34;Here&#39;s the spec, take it or leave it&#34;&#xA;&gt; attitude. What&#39;s the point of having a BIP process if the discussion just&#xA;&gt; comes down to &#34;We think more is better. We don&#39;t care what you think.&#34;&#xA;&#xA;It is a proposal and we are discussing it. You first brought up some&#xA;criticisms in private, and I agreed with several things you said.&#xA;&#xA;But it remains the proposal of a few people including me, and I do not&#xA;agree with the specific suggestion of reducing the security target for&#xA;witness scripts to 80 bits.&#xA;&#xA;We are not deciding what the system will be. We&#39;re making a proposal, and&#xA;hope that due to its technical merit, the ecosystem will adopt it. You&#39;re&#xA;free to participate in that discussion.&#xA;&#xA;-- &#xA;Pieter&#xA;-------------- next part --------------&#xA;An HTML attachment was scrubbed...&#xA;URL: &lt;http://lists.linuxfoundation.org/pipermail/bitcoin-dev/attachments/20160108/2420393c/attachment.html&gt;</html></oembed>