SHA1 collisions make Git vulnerable to attakcs by third-parties, not just repo maintainers



Summary:

In an email conversation, Steve Davis expressed his opinion that posting instructions about potential attacks without remediation is unethical. However, Peter Todd disagreed and stated that it is important to expose such attacks and their risks to the public so that people can develop mitigations. He argued that keeping details secret could actually be more harmful in situations where the attacks are not yet practical. When asked about the best practical response to such issues, Peter suggested deploying segwit's 256-bit digests, which is already fully coded and ready to deploy, with the exception of a new address format that is being actively worked on.


Updated on: 2023-06-11T21:48:39.582059+00:00