SHA1 collisions make Git vulnerable to attakcs by third-parties, not just repo maintainers



Summary:

In an email thread between Peter Todd and Steve Davis, the two discussed the ethics of posting instructions for potential attacks without providing a remedy. Todd argued that exposing such vulnerabilities is important to encourage the development of mitigations, especially when the computational costs of attacks limit their real-world impact. Davis agreed with the need for exposure but also hoped for a discussion on practical responses to the issue.Todd suggested deploying segwit's 256-bit digests as a response to potential attacks, which has already been fully coded and just needs a new address format. However, Davis expressed concerns about the time it would take to reach critical mass with segwit and proposed exploring alternative approaches for a fair assessment of the best response.


Updated on: 2023-06-11T21:48:45.821308+00:00