>Can I try it out for myself? Since our attack on SHA-1 has pratical implications, in order to make sure proper countermeasures have been pushed we will wait for some time before releasing source code that allows to generate SHA-1 chosen-prefix collisions. Sigh. Again with this idiocy. All instances where the adversary is capable of launching this attack financially mean they also have the capability to write the exp…
Targets worth attacking at a high financial cost will most likely be the first to take measures against this attack.
The kind of target that takes a longer time to switch most likely isn't worth attacking unless it's a very cheap and fast operation.
And the longer you spend developing an exploit, the less viable the attack will become.