<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom">
  <updated></updated>
  <generator>https://nostr.ae</generator>

  <title>Nostr notes by </title>
  <author>
    <name></name>
  </author>
  <link rel="self" type="application/atom+xml" href="https://nostr.ae/npub136r0c946pguuzps5eu3tv47jh5pyfxvmty9wt7prgj3krm2py8eqwpj3wf.rss" />
  <link href="https://nostr.ae/npub136r0c946pguuzps5eu3tv47jh5pyfxvmty9wt7prgj3krm2py8eqwpj3wf" />
  <id>https://nostr.ae/npub136r0c946pguuzps5eu3tv47jh5pyfxvmty9wt7prgj3krm2py8eqwpj3wf</id>
  <icon></icon>
  <logo></logo>




  <entry>
    <id>https://nostr.ae/nevent1qqsqhfmzlar9qe4fhf8rah7tlrxkn3g3fjl8my55tf276ju3patt4ggzyz8gdlqkhg9rnsgxzn8j9djh627sy3yendvs4e0cydz2xc0dgysly2e4wx5</id>
    
      <title type="html">📅 Original date posted:2015-02-10 📝 Original ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsqhfmzlar9qe4fhf8rah7tlrxkn3g3fjl8my55tf276ju3patt4ggzyz8gdlqkhg9rnsgxzn8j9djh627sy3yendvs4e0cydz2xc0dgysly2e4wx5" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsryvs94yp0m04h4s9ds7389m735nxmle995zkz7qlxrjvg6z07phqs6kcz4&#39;&gt;nevent1q…kcz4&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;📅 Original date posted:2015-02-10&lt;br/&gt;📝 Original message:2015-02-10 12:12 GMT&#43;01:00 Natanael &amp;lt;natanael.l at gmail.com&amp;gt;:&lt;br/&gt;&amp;gt; Den 10 feb 2015 11:48 skrev &amp;#34;MⒶrtin HⒶboⓋštiak&amp;#34;&lt;br/&gt;&amp;gt; &amp;lt;martin.habovstiak at gmail.com&amp;gt;:&lt;br/&gt;&amp;gt;&amp;gt;&lt;br/&gt;&amp;gt;&amp;gt; I still don&amp;#39;t understand. The website can have this information&lt;br/&gt;&amp;gt;&amp;gt; available. This is exactly what e-bay does - it displays shipping&lt;br/&gt;&amp;gt;&amp;gt; information to my country before I do anything. What&amp;#39;s the problem?&lt;br/&gt;&amp;gt;&amp;gt;&lt;br/&gt;&amp;gt;&amp;gt; Also with other stuff, website can do it and browser extension can do&lt;br/&gt;&amp;gt;&amp;gt; it too without messing with Bitcoin.&lt;br/&gt;&amp;gt;&lt;br/&gt;&amp;gt; 1: IP isn&amp;#39;t guaranteed to work correctly both because you might be using a&lt;br/&gt;&amp;gt; VPN out Tor.&lt;br/&gt;&lt;br/&gt;Still possible using web browser extension.&lt;br/&gt;&amp;gt;&lt;br/&gt;&amp;gt; 2: Yes, the site can display all options right away, but are you willing to&lt;br/&gt;&amp;gt; read all of them too?&lt;br/&gt;&lt;br/&gt;Why not? And again, browser extension can do it without bitcoin wallet&lt;br/&gt;- no need to connect unrelated things.&lt;br/&gt;&amp;gt;&lt;br/&gt;&amp;gt; 3: Detailed information is not necessary, nor does it have to be unprompted.&lt;br/&gt;&amp;gt; It doesn&amp;#39;t need to tell you more than which country you are in. It can even&lt;br/&gt;&amp;gt; prompt you with a popup that has a slider that shows exactly how much&lt;br/&gt;&amp;gt; information and of what kind you&amp;#39;re about to share (including none, if&lt;br/&gt;&amp;gt; that&amp;#39;s your choice).&lt;br/&gt;&amp;gt;&lt;br/&gt;&amp;gt; 4: It doesn&amp;#39;t need to share raw data. Take a look at anonymous credentials:&lt;br/&gt;&amp;gt; &lt;a href=&#34;http://www.zurich.ibm.com/idemix/&#34;&gt;http://www.zurich.ibm.com/idemix/&lt;/a&gt;&lt;br/&gt;&amp;gt; &lt;a href=&#34;https://eprint.iacr.org/2013/622.pdf&#34;&gt;https://eprint.iacr.org/2013/622.pdf&lt;/a&gt;&lt;br/&gt;&amp;gt;&lt;br/&gt;&amp;gt; 5: It can wait for prompting until you add the first item to the cart.&lt;br/&gt;&lt;br/&gt;Everything you described is possible without Bitcoin involved - why&lt;br/&gt;would we mix unrelated things?&lt;br/&gt;&lt;br/&gt;P.S.: I believe in Unix philosophy. ;)
    </content>
    <updated>2023-06-07T15:30:01Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqstqz9fa52puz9tn8ykhzy608yrzulhlry03hvkqvnkcqw08u67qvqzyz8gdlqkhg9rnsgxzn8j9djh627sy3yendvs4e0cydz2xc0dgyslynn5xvk</id>
    
      <title type="html">📅 Original date posted:2015-02-10 📝 Original message:Why ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqstqz9fa52puz9tn8ykhzy608yrzulhlry03hvkqvnkcqw08u67qvqzyz8gdlqkhg9rnsgxzn8j9djh627sy3yendvs4e0cydz2xc0dgyslynn5xvk" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsyfxplqj86p7kcpu83p32agdgdut89cnh9f42cfaud00vgcpm9eqqm92a68&#39;&gt;nevent1q…2a68&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;📅 Original date posted:2015-02-10&lt;br/&gt;📝 Original message:Why would anyone want to do anything about payment before choosing&lt;br/&gt;what he wants to buy and for what price? I&amp;#39;ve never used Amazon but&lt;br/&gt;isn&amp;#39;t filling a form with shipping information enough?&lt;br/&gt;&lt;br/&gt;2015-02-10 11:21 GMT&#43;01:00 Natanael &amp;lt;natanael.l at gmail.com&amp;gt;:&lt;br/&gt;&amp;gt; BIP70 is a protocol for getting a user&amp;#39;s wallet client communicate with a&lt;br/&gt;&amp;gt; merchant&amp;#39;s server in order to agree on details like where to send the&lt;br/&gt;&amp;gt; payment, how much to send, what the shipping address is, sending a receipt&lt;br/&gt;&amp;gt; back, and much more using various extensions that adds more functionality.&lt;br/&gt;&amp;gt;&lt;br/&gt;&amp;gt; There could even be advanced functionality for automatically negotiating&lt;br/&gt;&amp;gt; terms. One example could be selecting a multisignature arbitrator both sides&lt;br/&gt;&amp;gt; trust. Another could be to agree on the speed and type of delivery. Many&lt;br/&gt;&amp;gt; more types of decisions could be automatically agreed upon.&lt;br/&gt;&amp;gt;&lt;br/&gt;&amp;gt; But as it is now, it is designed to be initiated at the time of payment. If&lt;br/&gt;&amp;gt; you always want next-day delivery from online stores then you won&amp;#39;t always&lt;br/&gt;&amp;gt; know if that&amp;#39;s an option until you&amp;#39;ve filled the digital basket and gone&lt;br/&gt;&amp;gt; through checkout. If you only want to shop with an arbitrator involved same&lt;br/&gt;&amp;gt; thing applies.&lt;br/&gt;&amp;gt;&lt;br/&gt;&amp;gt; Everything that BIP70 enables happens at the last step only, as it is right&lt;br/&gt;&amp;gt; now.&lt;br/&gt;&amp;gt;&lt;br/&gt;&amp;gt; If there could be a BIP70 HTML tag on web shops that automatically triggered&lt;br/&gt;&amp;gt; your wallet as soon as you visit the page, it would be possible for a&lt;br/&gt;&amp;gt; browser extension that talks to your wallet to tell you right away if the&lt;br/&gt;&amp;gt; web shop you&amp;#39;re currently looking at has terms you consider acceptable or&lt;br/&gt;&amp;gt; not (note: if your wallet client isn&amp;#39;t installed on or linked to that same&lt;br/&gt;&amp;gt; machine, a visible Qr code would be an acceptable alternative which you can&lt;br/&gt;&amp;gt; scan in advance before you start shopping). This notification can even be&lt;br/&gt;&amp;gt; automatically updated as you add and remove things from your cart and&lt;br/&gt;&amp;gt; details like shipping options change.&lt;br/&gt;&amp;gt;&lt;br/&gt;&amp;gt; This would massively simplify the shipping experience and make every web&lt;br/&gt;&amp;gt; shop feel like Amazon.&lt;br/&gt;&amp;gt;&lt;br/&gt;&amp;gt; Of course this has privacy implications and increases exposure to potential&lt;br/&gt;&amp;gt; wallet exploits, but the wallet can ask you if you intend to shop or not at&lt;br/&gt;&amp;gt; each site before it even connects and send any information at all in order&lt;br/&gt;&amp;gt; to mitigate both of those problems. This way it should be reasonably safe.&lt;br/&gt;&amp;gt;&lt;br/&gt;&amp;gt; Another option would be to automatically connect but limit what data is sent&lt;br/&gt;&amp;gt; in order to remain privacy preserving, until the user agrees to send private&lt;br/&gt;&amp;gt; information.&lt;br/&gt;&amp;gt;&lt;br/&gt;&amp;gt; This second method would also open up for the merchant to other send&lt;br/&gt;&amp;gt; relevant information such as details about various certifications from third&lt;br/&gt;&amp;gt; parties, which can include a certification that shows they have been been&lt;br/&gt;&amp;gt; audited and approved by by entity X for purpose Y. If your wallet has that&lt;br/&gt;&amp;gt; entity whitelisted it will show you that certificate (for example &amp;#34;Acme&lt;br/&gt;&amp;gt; Audits have audited and approves of Merchant M&amp;#39;s privacy policy and data&lt;br/&gt;&amp;gt; protection&amp;#34;). With a list of predefined types of certifications that the&lt;br/&gt;&amp;gt; wallet understand and accepts, it could (by choice of the user) require a&lt;br/&gt;&amp;gt; certificate to be present to even allow you to make a purchase (lack of&lt;br/&gt;&amp;gt; required certifications would result in automatic denial). No certificate =&lt;br/&gt;&amp;gt; your wallet never proceed to send private information.&lt;br/&gt;&amp;gt;&lt;br/&gt;&amp;gt; Thoughts?&lt;br/&gt;&amp;gt;&lt;br/&gt;&amp;gt; - Sent from my tablet&lt;br/&gt;&amp;gt;&lt;br/&gt;&amp;gt;&lt;br/&gt;&amp;gt; ------------------------------------------------------------------------------&lt;br/&gt;&amp;gt; Dive into the World of Parallel Programming. The Go Parallel Website,&lt;br/&gt;&amp;gt; sponsored by Intel and developed in partnership with Slashdot Media, is your&lt;br/&gt;&amp;gt; hub for all things parallel software development, from weekly thought&lt;br/&gt;&amp;gt; leadership blogs to news, videos, case studies, tutorials and more. Take a&lt;br/&gt;&amp;gt; look and join the conversation now. &lt;a href=&#34;http://goparallel.sourceforge.net/&#34;&gt;http://goparallel.sourceforge.net/&lt;/a&gt;&lt;br/&gt;&amp;gt; _______________________________________________&lt;br/&gt;&amp;gt; Bitcoin-development mailing list&lt;br/&gt;&amp;gt; Bitcoin-development at lists.sourceforge.net&lt;br/&gt;&amp;gt; &lt;a href=&#34;https://lists.sourceforge.net/lists/listinfo/bitcoin-development&#34;&gt;https://lists.sourceforge.net/lists/listinfo/bitcoin-development&lt;/a&gt;&lt;br/&gt;&amp;gt;
    </content>
    <updated>2023-06-07T15:30:00Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsxleqqnn2smxn6de66ewd2yrvhnv9p5htv64ym76z5aj8rrdj07tgzyz8gdlqkhg9rnsgxzn8j9djh627sy3yendvs4e0cydz2xc0dgysly6tgddm</id>
    
      <title type="html">📅 Original date posted:2015-02-10 📝 Original message:I ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsxleqqnn2smxn6de66ewd2yrvhnv9p5htv64ym76z5aj8rrdj07tgzyz8gdlqkhg9rnsgxzn8j9djh627sy3yendvs4e0cydz2xc0dgysly6tgddm" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqs8w5kk8nl44xy0tkwl6ynfv0urugsk4l2mx95mxv8pddleg4w2rcsltztrc&#39;&gt;nevent1q…ztrc&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;📅 Original date posted:2015-02-10&lt;br/&gt;📝 Original message:I still don&amp;#39;t understand. The website can have this information&lt;br/&gt;available. This is exactly what e-bay does - it displays shipping&lt;br/&gt;information to my country before I do anything. What&amp;#39;s the problem?&lt;br/&gt;&lt;br/&gt;Also with other stuff, website can do it and browser extension can do&lt;br/&gt;it too without messing with Bitcoin.&lt;br/&gt;&lt;br/&gt;2015-02-10 11:41 GMT&#43;01:00 Natanael &amp;lt;natanael.l at gmail.com&amp;gt;:&lt;br/&gt;&amp;gt; Den 10 feb 2015 11:34 skrev &amp;#34;MⒶrtin HⒶboⓋštiak&amp;#34;&lt;br/&gt;&amp;gt; &amp;lt;martin.habovstiak at gmail.com&amp;gt;:&lt;br/&gt;&amp;gt;&amp;gt;&lt;br/&gt;&amp;gt;&amp;gt; Why would anyone want to do anything about payment before choosing&lt;br/&gt;&amp;gt;&amp;gt; what he wants to buy and for what price? I&amp;#39;ve never used Amazon but&lt;br/&gt;&amp;gt;&amp;gt; isn&amp;#39;t filling a form with shipping information enough?&lt;br/&gt;&amp;gt;&lt;br/&gt;&amp;gt; That&amp;#39;s not what this is about.&lt;br/&gt;&amp;gt;&lt;br/&gt;&amp;gt; BIP70 isn&amp;#39;t just payment, it is about communication the terms of the sale.&lt;br/&gt;&amp;gt;&lt;br/&gt;&amp;gt; Let&amp;#39;s say you&amp;#39;re visiting an international webshop. But they don&amp;#39;t ship to&lt;br/&gt;&amp;gt; your country. Wouldn&amp;#39;t you want to know that before your start filling the&lt;br/&gt;&amp;gt; cart? With this, your wallet / browser extension could tell you right away&lt;br/&gt;&amp;gt; that you can&amp;#39;t shop there. No time wasted!&lt;br/&gt;&amp;gt;&lt;br/&gt;&amp;gt; That&amp;#39;s just one requirement of many where you would benefit from being told&lt;br/&gt;&amp;gt; right away if it is acceptable for both parties or not.
    </content>
    <updated>2023-06-07T15:30:00Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsr54cna08a4yzugquul36vy8r0rkru84pyswyvpwrg7g3jvkqsgfczyz8gdlqkhg9rnsgxzn8j9djh627sy3yendvs4e0cydz2xc0dgyslygqat4z</id>
    
      <title type="html">📅 Original date posted:2015-02-05 📝 Original ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsr54cna08a4yzugquul36vy8r0rkru84pyswyvpwrg7g3jvkqsgfczyz8gdlqkhg9rnsgxzn8j9djh627sy3yendvs4e0cydz2xc0dgyslygqat4z" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqswrdr6s7yggjykhalg3tqf8a5xd6ep32ugqgsqkq395jwlcfxfamgq0jgpr&#39;&gt;nevent1q…jgpr&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;📅 Original date posted:2015-02-05&lt;br/&gt;📝 Original message:That&amp;#39;s exactly what I though when seeing the RedPhone code, but after&lt;br/&gt;I studied the commit protocol I realized it&amp;#39;s actually secure and&lt;br/&gt;convenient way to do it. You should do that too. :)&lt;br/&gt;&lt;br/&gt;Shortly, how it works:&lt;br/&gt;The initiator of the connection sends commit message containing the&lt;br/&gt;hash of his temporary public ECDH part, second party sends back their&lt;br/&gt;public ECDH part and then initiator sends his public ECDH part in&lt;br/&gt;open. All three messages are hashed together and the first two bytes&lt;br/&gt;are used to select two words from a shared dictionary which are&lt;br/&gt;displayed on the screen of both the initiator and the second party.&lt;br/&gt;The parties communicate those two words and verify they match.&lt;br/&gt;&lt;br/&gt;If an attacker wants to do MITM, he has a chance of choosing right&lt;br/&gt;public parts 1:65536. There is no way to brute-force it, since that&lt;br/&gt;would be noticed immediately. If instead of two words based on the&lt;br/&gt;first two bytes, four words from BIP39 wordlist were chosen, it would&lt;br/&gt;provide entropy of 44 bits which I believe should be enough even for&lt;br/&gt;paranoid people.&lt;br/&gt;&lt;br/&gt;How this would work in Bitcoin payment scenario: user&amp;#39;s phone&lt;br/&gt;broadcasts his name, merchant inputs amount and selects the name from&lt;br/&gt;the list, commit message is sent (and then the remaining two&lt;br/&gt;messages), merchant spells four words he sees on the screen and buyer&lt;br/&gt;confirms transaction after verifying that words match.&lt;br/&gt;&lt;br/&gt;2015-02-06 0:46 GMT&#43;01:00 Eric Voskuil &amp;lt;eric at voskuil.org&amp;gt;:&lt;br/&gt;&amp;gt; On 02/05/2015 03:36 PM, MⒶrtin HⒶboⓋštiak wrote:&lt;br/&gt;&amp;gt;&amp;gt;&amp;gt; A BIP-70 signed payment request in the initial broadcast can resolve the&lt;br/&gt;&amp;gt;&amp;gt;&amp;gt; integrity issues, but because of the public nature of the broadcast&lt;br/&gt;&amp;gt;&amp;gt;&amp;gt; coupled with strong public identity, the privacy compromise is much&lt;br/&gt;&amp;gt;&amp;gt;&amp;gt; worse. Now transactions are cryptographically tainted.&lt;br/&gt;&amp;gt;&amp;gt;&amp;gt;&lt;br/&gt;&amp;gt;&amp;gt;&amp;gt; This is also the problem with BIP-70 over the web. TLS and other&lt;br/&gt;&amp;gt;&amp;gt;&amp;gt; security precautions aside, an interloper on the communication, desktop,&lt;br/&gt;&amp;gt;&amp;gt;&amp;gt; datacenter, etc., can capture payment requests and strongly correlate&lt;br/&gt;&amp;gt;&amp;gt;&amp;gt; transactions to identities in an automated manner. The payment request&lt;br/&gt;&amp;gt;&amp;gt;&amp;gt; must be kept private between the parties, and that&amp;#39;s hard to do.&lt;br/&gt;&amp;gt;&amp;gt;&lt;br/&gt;&amp;gt;&amp;gt; What about using encryption with forward secrecy? Merchant would&lt;br/&gt;&amp;gt;&amp;gt; generate signed request containing public ECDH part, buyer would send&lt;br/&gt;&amp;gt;&amp;gt; back transaction encrypted with ECDH and his public ECDH part. If&lt;br/&gt;&amp;gt;&amp;gt; receiving address/amount is meant to be private, use commit protocol&lt;br/&gt;&amp;gt;&amp;gt; (see ZRTP/RedPhone) and short authentication phrase (which is hard to&lt;br/&gt;&amp;gt;&amp;gt; spoof thanks to commit protocol - see RedPhone)?&lt;br/&gt;&amp;gt;&lt;br/&gt;&amp;gt; Hi Martin,&lt;br/&gt;&amp;gt;&lt;br/&gt;&amp;gt; The problem is that you need to verify the ownership of the public key.&lt;br/&gt;&amp;gt; A MITM can substitute the key. If you don&amp;#39;t have verifiable identity&lt;br/&gt;&amp;gt; associated with the public key (PKI/WoT), you need a shared secret (such&lt;br/&gt;&amp;gt; as a secret phrase). But the problem is then establishing that secret&lt;br/&gt;&amp;gt; over a public channel.&lt;br/&gt;&amp;gt;&lt;br/&gt;&amp;gt; You can bootstrap a private session over the untrusted network using a&lt;br/&gt;&amp;gt; trusted public key (PKI/WoT). But the presumption is that you are&lt;br/&gt;&amp;gt; already doing this over the web (using TLS). That process is subject to&lt;br/&gt;&amp;gt; attack at the CA. WoT is not subject to a CA attack, because it&amp;#39;s&lt;br/&gt;&amp;gt; decentralized. But it&amp;#39;s also not sufficiently deployed for some scenarios.&lt;br/&gt;&amp;gt;&lt;br/&gt;&amp;gt; e&lt;br/&gt;&amp;gt;
    </content>
    <updated>2023-06-07T15:29:46Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsfw9unm58k8l0fk526cameh4cfn4cc6ms3w9fkkeqgscy5prpxkpqzyz8gdlqkhg9rnsgxzn8j9djh627sy3yendvs4e0cydz2xc0dgyslym3j4ya</id>
    
      <title type="html">📅 Original date posted:2015-02-05 📝 Original message:I ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsfw9unm58k8l0fk526cameh4cfn4cc6ms3w9fkkeqgscy5prpxkpqzyz8gdlqkhg9rnsgxzn8j9djh627sy3yendvs4e0cydz2xc0dgyslym3j4ya" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqs8qeqyytlnyrgdfslk4642s5tcdj76wj78ujsjd7lmqpc2gkc3yqgvxxuty&#39;&gt;nevent1q…xuty&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;📅 Original date posted:2015-02-05&lt;br/&gt;📝 Original message:I would like to shortly express my opinion:&lt;br/&gt;&lt;br/&gt;- Having BT as an alternative is good idea but it must be secure enough&lt;br/&gt;- Signed BIP70 should be enough. I see only two issues regarding BIP70&lt;br/&gt;(but they apply also to TCP/IP, not just BT): key revocations and MITM&lt;br/&gt;attacks by governments.&lt;br/&gt;- Broadcasting faces is very bad idea IMHO.&lt;br/&gt;- Comparing addresses seems complicated but if hash was displayed as a&lt;br/&gt;unique, picture hard to be mistake or long phrase, it could be more&lt;br/&gt;convenient.&lt;br/&gt;- Maybe storing public key (I do NOT mean bitcoin address!) of&lt;br/&gt;merchant after successful transaction is good compromise?&lt;br/&gt;&lt;br/&gt;Another idea: I noticed it&amp;#39;s extremely easy to compare two strings if&lt;br/&gt;they are the same size (in terms of millimeters, not number of&lt;br/&gt;characters). If the hash of signing key was printed on a sign near the&lt;br/&gt;POS in specified size (90% of smallest available screen?) and phone&lt;br/&gt;would scale correctly, just putting the phone near the sign would be&lt;br/&gt;enough to instantly spot whether the hashes are same.&lt;br/&gt;&lt;br/&gt;Maybe instead of hex/base58 hash encoding use colored barcode. But I&amp;#39;m&lt;br/&gt;not sure if it would improve things.&lt;br/&gt;&lt;br/&gt;2015-02-05 23:49 GMT&#43;01:00 Roy Badami &amp;lt;roy at gnomon.org.uk&amp;gt;:&lt;br/&gt;&amp;gt; Personally I like the simplicity of tapping two phones together to&lt;br/&gt;&amp;gt; make payment - it should be quicker and easier than scanning QR codes&lt;br/&gt;&amp;gt; and it&amp;#39;s a trust model that&amp;#39;s hard to misunderstand.&lt;br/&gt;&amp;gt;&lt;br/&gt;&amp;gt; Is NFC good enough for that?  I fear even with NFC it is possible to&lt;br/&gt;&amp;gt; produce a device with longer range than one would expect.  What&lt;br/&gt;&amp;gt; happened to the idea of tapping two devices together and then&lt;br/&gt;&amp;gt; comparing the timing of the tap (as detected by the phones&amp;#39;&lt;br/&gt;&amp;gt; accelerometers) to make spoofing a transaction harder?  I remember&lt;br/&gt;&amp;gt; hearing about that years ago - is that still a thing?&lt;br/&gt;&amp;gt;&lt;br/&gt;&amp;gt; roy&lt;br/&gt;&amp;gt;&lt;br/&gt;&amp;gt; On Thu, Feb 05, 2015 at 02:10:51PM -0800, Eric Voskuil wrote:&lt;br/&gt;&amp;gt;&amp;gt; A MITM can receive the initial broadcast and then spoof it by jamming the original. You then only see one.&lt;br/&gt;&amp;gt;&amp;gt;&lt;br/&gt;&amp;gt;&amp;gt; e&lt;br/&gt;&amp;gt;&amp;gt;&lt;br/&gt;&amp;gt;&amp;gt; &amp;gt; On Feb 5, 2015, at 2:07 PM, Paul Puey &amp;lt;paul at airbitz.co&amp;gt; wrote:&lt;br/&gt;&amp;gt;&amp;gt; &amp;gt;&lt;br/&gt;&amp;gt;&amp;gt; &amp;gt; So if you picked up the BLE broadcast request. All you know is that *someone* within 100m is requesting bitcoin at a certain address. Not necessarily who. The *name* is both optional, and possibly just a *handle* of the user. If I&amp;#39;m sitting 5 ft away from someone at dinner and wanted to pay them via BLE, I might see &amp;#34;Monkey Dude&amp;#34; on my list and simply ask him &amp;#34;is that you?&amp;#34; If so, I send it. If there are two &amp;#34;Monkey Dude&amp;#39;s&amp;#34; Then I have to bother with the address prefix, but not otherwise.&lt;br/&gt;&amp;gt;&amp;gt; &amp;gt;&lt;br/&gt;&amp;gt;&amp;gt; &amp;gt;&amp;gt; On Thu, Feb 5, 2015 at 1:46 PM, Eric Voskuil &amp;lt;eric at voskuil.org&amp;gt; wrote:&lt;br/&gt;&amp;gt;&amp;gt; &amp;gt;&amp;gt; BLE has an advertised range of over 100m.&lt;br/&gt;&amp;gt;&amp;gt; &amp;gt;&amp;gt;&lt;br/&gt;&amp;gt;&amp;gt; &amp;gt;&amp;gt; &lt;a href=&#34;http://www.bluetooth.com/Pages/low-energy-tech-info.aspx&#34;&gt;http://www.bluetooth.com/Pages/low-energy-tech-info.aspx&lt;/a&gt;&lt;br/&gt;&amp;gt;&amp;gt; &amp;gt;&amp;gt;&lt;br/&gt;&amp;gt;&amp;gt; &amp;gt;&amp;gt; In the case of mass surveillance that range could most likely be extended dramatically by the reviewer. I&amp;#39;ve seen  WiFi ranges of over a mile with a strong (not FCC approved) receiver.&lt;br/&gt;&amp;gt;&amp;gt; &amp;gt;&amp;gt;&lt;br/&gt;&amp;gt;&amp;gt; &amp;gt;&amp;gt; WiFi hotspots don&amp;#39;t have strong identity or a guaranteed position, so they can&amp;#39;t be trusted for location.&lt;br/&gt;&amp;gt;&amp;gt; &amp;gt;&amp;gt;&lt;br/&gt;&amp;gt;&amp;gt; &amp;gt;&amp;gt; e&lt;br/&gt;&amp;gt;&amp;gt; &amp;gt;&amp;gt;&lt;br/&gt;&amp;gt;&amp;gt; &amp;gt;&amp;gt; On Feb 5, 2015, at 1:36 PM, Mike Hearn &amp;lt;mike at plan99.net&amp;gt; wrote:&lt;br/&gt;&amp;gt;&amp;gt; &amp;gt;&amp;gt;&lt;br/&gt;&amp;gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;&amp;gt; This sounds horrible. You could basically monitor anyone with a wallet in a highly populated area and track them super easily by doing facial recognition.&lt;br/&gt;&amp;gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;&lt;br/&gt;&amp;gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt; We&amp;#39;re talking about BLE, still? The radio tech that runs in the so called &amp;#34;junk bands&amp;#34; because propagation is so poor?&lt;br/&gt;&amp;gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;&lt;br/&gt;&amp;gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt; My watch loses its connection to my phone if I just put it down and walk around my apartment. I&amp;#39;m all for reasonable paranoia, but Bluetooth isn&amp;#39;t going to be enabling mass surveillance any time soon. It barely goes through air, let alone walls.&lt;br/&gt;&amp;gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;&lt;br/&gt;&amp;gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt; Anyway, whatever. I&amp;#39;m just bouncing around ideas for faster user interfaces. You could always switch it off or set it to be triggered by the presence of particular wifi hotspots, if you don&amp;#39;t mind an initial bit of setup.&lt;br/&gt;&amp;gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;&lt;br/&gt;&amp;gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt; Back on topic - the debate is interesting, but I think to get this to the stage of being a BIP we&amp;#39;d need at least another wallet to implement it? Then I guess a BIP would be useful regardless of the design issues. The prefix matching still feels flaky to me but it&amp;#39;s hard to know if you could really swipe payments out of the air in practice, without actually trying it.&lt;br/&gt;&amp;gt;&amp;gt; &amp;gt;&lt;br/&gt;&amp;gt;&lt;br/&gt;&amp;gt;&amp;gt; ------------------------------------------------------------------------------&lt;br/&gt;&amp;gt;&amp;gt; Dive into the World of Parallel Programming. The Go Parallel Website,&lt;br/&gt;&amp;gt;&amp;gt; sponsored by Intel and developed in partnership with Slashdot Media, is your&lt;br/&gt;&amp;gt;&amp;gt; hub for all things parallel software development, from weekly thought&lt;br/&gt;&amp;gt;&amp;gt; leadership blogs to news, videos, case studies, tutorials and more. Take a&lt;br/&gt;&amp;gt;&amp;gt; look and join the conversation now. &lt;a href=&#34;http://goparallel.sourceforge.net/&#34;&gt;http://goparallel.sourceforge.net/&lt;/a&gt;&lt;br/&gt;&amp;gt;&lt;br/&gt;&amp;gt;&amp;gt; _______________________________________________&lt;br/&gt;&amp;gt;&amp;gt; Bitcoin-development mailing list&lt;br/&gt;&amp;gt;&amp;gt; Bitcoin-development at lists.sourceforge.net&lt;br/&gt;&amp;gt;&amp;gt; &lt;a href=&#34;https://lists.sourceforge.net/lists/listinfo/bitcoin-development&#34;&gt;https://lists.sourceforge.net/lists/listinfo/bitcoin-development&lt;/a&gt;&lt;br/&gt;&amp;gt;&lt;br/&gt;&amp;gt;&lt;br/&gt;&amp;gt; ------------------------------------------------------------------------------&lt;br/&gt;&amp;gt; Dive into the World of Parallel Programming. The Go Parallel Website,&lt;br/&gt;&amp;gt; sponsored by Intel and developed in partnership with Slashdot Media, is your&lt;br/&gt;&amp;gt; hub for all things parallel software development, from weekly thought&lt;br/&gt;&amp;gt; leadership blogs to news, videos, case studies, tutorials and more. Take a&lt;br/&gt;&amp;gt; look and join the conversation now. &lt;a href=&#34;http://goparallel.sourceforge.net/&#34;&gt;http://goparallel.sourceforge.net/&lt;/a&gt;&lt;br/&gt;&amp;gt; _______________________________________________&lt;br/&gt;&amp;gt; Bitcoin-development mailing list&lt;br/&gt;&amp;gt; Bitcoin-development at lists.sourceforge.net&lt;br/&gt;&amp;gt; &lt;a href=&#34;https://lists.sourceforge.net/lists/listinfo/bitcoin-development&#34;&gt;https://lists.sourceforge.net/lists/listinfo/bitcoin-development&lt;/a&gt;
    </content>
    <updated>2023-06-07T15:29:43Z</updated>
  </entry>

</feed>