mirror of
https://github.com/bitcoin/bips.git
synced 2026-06-01 17:15:27 +00:00
This is supposed to supersede https://github.com/sipa/bips/pull/158. I tried to say this carefully. I don't think that multiparty signing is in general broken with short hashes. For example the attack in #158 could be avoided by letting everybody not only commit to the nonce but also to the message. It's just that using a collision-resistant hash just eliminates the problem entirely...
32 KiB
32 KiB