3 ms·
Pretty sure the accepted justification for double-SHA is to prevent length-extension attacks.
by makeworld 3y ago
Pretty sure the accepted justification for double-SHA is to prevent length-extension attacks.
- eimrine 3y agoHow is it possible if a length of input data going to SHA-256 is one of the required inputs for SHA-256?
- adastra22 3y agoYou are correct in general, but all bitcoin data structures are self-synchronized, so length extension is not possible.
- eimrine 3y agoAre you sure he is correct in general? I suppose he supposed the length extension attack not on Bitcoin (because all Bitcoin data are self-synchronized) but on anything else using blockchain as a rainbow-table.
- adastra22 3y agoYes, in general anything being hashed that is subject to length extension ought to be double hashed. And most things are subject to length extension, often in surprising ways. So a good rule of thumb is to always double hash. But in this case, after 15 years of analysis, we can say with confidence that the double hashing bitcoin does is redundant.