Matt Green: In crypto we have the idea that hash function collisions should be really hard to find, even if they're 'useless'. [...] [A real-world collision attack] is the equivalent of finding out that your scalpel wasn't sterilized properly. It may not verifiably have germs on it, but the whole instrument