SHA1 collisions make Git vulnerable to attakcs by third-parties, not just repo maintainers



Summary:

On Feb 26, 2017, Pieter Wuille raised concerns about the 80-bit collision attack which applies only to jointly constructed addresses like multisig P2SH, not single-key ones. However, he was less convinced about the part where SHA1 vs RIPEMD was concerned. He was checking his own numbers and could see a vector. If RIPEMD were weakened in any way, single-key transactions could suddenly become badly exposed.


Updated on: 2023-06-11T21:48:50.784723+00:00