SHA1 collisions make Git vulnerable to attakcs by third-parties, not just repo maintainers



Summary:

In a discussion on the bitcoin-dev mailing list, the security level of RIPEMD160(SHA256(msg)) was debated in relation to Bitcoin addresses. While collisions are possible, Peter Todd argued that it does not cause harm to the Bitcoin network itself, and that the 160-bit security level is sufficient for pay-to-pubkey-hash transactions. However, more complex contracts such as P2SH 2-of-2 multisig can be vulnerable to collision attacks, as pointed out by Russell O'Connor. Todd acknowledged this issue and mentioned the commit-reveal mitigation. The original post also included information about the sender's skills and projects.


Updated on: 2023-06-11T21:48:33.754222+00:00