<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom">
  <updated></updated>
  <generator>https://nostr.ae</generator>

  <title>Nostr notes by </title>
  <author>
    <name></name>
  </author>
  <link rel="self" type="application/atom+xml" href="https://nostr.ae/npub1pa6l5jatv92d4vzk566r58zjawpuu0we8nhrywfhp90f9948e0tsx3rxtp.rss" />
  <link href="https://nostr.ae/npub1pa6l5jatv92d4vzk566r58zjawpuu0we8nhrywfhp90f9948e0tsx3rxtp" />
  <id>https://nostr.ae/npub1pa6l5jatv92d4vzk566r58zjawpuu0we8nhrywfhp90f9948e0tsx3rxtp</id>
  <icon></icon>
  <logo></logo>




  <entry>
    <id>https://nostr.ae/nevent1qqsypm88eze588cjmlrwdrygv25w7fty02yqvk5pd9h53mv0f7vww6qzyq8ht7jt4ds4fk4s26ntgwsu2t4c8n3amy7wuv3exuy4ay5k5l9awgj0sha</id>
    
      <title type="html">📅 Original date posted:2014-04-22 📝 Original message:The ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsypm88eze588cjmlrwdrygv25w7fty02yqvk5pd9h53mv0f7vww6qzyq8ht7jt4ds4fk4s26ntgwsu2t4c8n3amy7wuv3exuy4ay5k5l9awgj0sha" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqs07qmm8npe20606n4jxu4hkjpjq9jy2ptgtvcfs8yyg5q0w8hgzwqewnd69&#39;&gt;nevent1q…nd69&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;📅 Original date posted:2014-04-22&lt;br/&gt;📝 Original message:The development of BitID has had some progress, and we have now a working&lt;br/&gt;wallet prototype based on Android Bitcoin Wallet (bitoinj).&lt;br/&gt;The user flow is quite nice and if you are curious here is a short video&lt;br/&gt;demonstration :&lt;br/&gt;&lt;a href=&#34;https://www.youtube.com/watch?v=3eepEWTnRTc&#34;&gt;https://www.youtube.com/watch?v=3eepEWTnRTc&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;By default, each new first auth request will create and save a new address&lt;br/&gt;(SQRL like). It could be based on BIP32, but this works also without.&lt;br/&gt;This requires to add metadata to addresses, as described here :&lt;br/&gt;&lt;a href=&#34;https://github.com/bitid/bitid/blob/master/bitid_metadata.md&#34;&gt;https://github.com/bitid/bitid/blob/master/bitid_metadata.md&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;It open also the fields for decentralized 2FA as well as &amp;#34;pay as guest&amp;#34;&lt;br/&gt;checkout in conjonction with BIP70 payment request.&lt;br/&gt;&lt;br/&gt;Eric&lt;br/&gt;&lt;br/&gt;&lt;br/&gt;&lt;br/&gt;On Tue, Apr 22, 2014 at 8:34 AM, Jan Møller &amp;lt;jan.moller at gmail.com&amp;gt; wrote:&lt;br/&gt;&lt;br/&gt;&amp;gt; The reason why client side certificates have never gained traction because&lt;br/&gt;&amp;gt; it is a pain to safely store/backup secrets.&lt;br/&gt;&amp;gt; In bitcoinland we are forced to solve the problem of safely storing&lt;br/&gt;&amp;gt; secrets, and over the years we have come up with software and hardware&lt;br/&gt;&amp;gt; solutions to make this safer and easier to manage for ordinary people.&lt;br/&gt;&amp;gt; Solving this is paramount to the success of Bitcoin, and nobody has solved&lt;br/&gt;&amp;gt; it before on a grand scale.&lt;br/&gt;&amp;gt;&lt;br/&gt;&amp;gt; I see no reason for forcing end users to use two different mechanisms for&lt;br/&gt;&amp;gt; safely managing secrets.&lt;br/&gt;&amp;gt;&lt;br/&gt;&amp;gt; I agree that using a bitcoin address for authentication purposes might be&lt;br/&gt;&amp;gt; confusing and potentially linking your funds with your identity. So I am&lt;br/&gt;&amp;gt; all for using something else than bitcoin addresses and bitcoin private&lt;br/&gt;&amp;gt; keys.&lt;br/&gt;&amp;gt;&lt;br/&gt;&amp;gt; With bip32 we have finally agreed on a mechanism for generating a&lt;br/&gt;&amp;gt; hierarchy of bitcoin private keys from a master seed. A similar approach&lt;br/&gt;&amp;gt; can be used for generating a parallel hierarchy for authentication&lt;br/&gt;&amp;gt; purposes.&lt;br/&gt;&amp;gt;&lt;br/&gt;&amp;gt; - Jan&lt;br/&gt;&amp;gt;&lt;br/&gt;&amp;gt;&lt;br/&gt;&amp;gt;&lt;br/&gt;-------------- next part --------------&lt;br/&gt;An HTML attachment was scrubbed...&lt;br/&gt;URL: &amp;lt;&lt;a href=&#34;http://lists.linuxfoundation.org/pipermail/bitcoin-dev/attachments/20140422/97fad26c/attachment.html&amp;gt&#34;&gt;http://lists.linuxfoundation.org/pipermail/bitcoin-dev/attachments/20140422/97fad26c/attachment.html&amp;gt&lt;/a&gt;;
    </content>
    <updated>2023-06-07T15:17:23Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsdt4ahldyugm3x7eppy9a5j5kc3s4mxcmmks0k2d7pqnj3p8ek4aczyq8ht7jt4ds4fk4s26ntgwsu2t4c8n3amy7wuv3exuy4ay5k5l9awk3z5dy</id>
    
      <title type="html">📅 Original date posted:2014-04-04 📝 Original message:On ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsdt4ahldyugm3x7eppy9a5j5kc3s4mxcmmks0k2d7pqnj3p8ek4aczyq8ht7jt4ds4fk4s26ntgwsu2t4c8n3amy7wuv3exuy4ay5k5l9awk3z5dy" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsgttxyf5fqvrjv4jdhdnxhhsvfndewkmqacnxrdm8h5mpyyqsyahssyl5c2&#39;&gt;nevent1q…l5c2&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;📅 Original date posted:2014-04-04&lt;br/&gt;📝 Original message:On Fri, Apr 4, 2014 at 4:51 PM, Mike Hearn &amp;lt;mike at plan99.net&amp;gt; wrote:&lt;br/&gt;&lt;br/&gt;&amp;gt;  My view on this is mainly about the UX and the fact everyone in&lt;br/&gt;&amp;gt;&amp;gt; Bitcoinland has a wallet.&lt;br/&gt;&amp;gt;&amp;gt;&lt;br/&gt;&amp;gt;&lt;br/&gt;&amp;gt; Well, yes, but we also have browsers too :)&lt;br/&gt;&amp;gt;&lt;br/&gt;&amp;gt;&lt;br/&gt;Yes, but no one will ever install a plug in.&lt;br/&gt;And all will update their wallets with the last version, including the auth&lt;br/&gt;protocol.&lt;br/&gt;&lt;br/&gt;&lt;br/&gt;&amp;gt; I don&amp;#39;t want to suggest the problem is unimportant - I&amp;#39;d love it if the&lt;br/&gt;&amp;gt; world could move beyond passwords. But I have many scars from my time in&lt;br/&gt;&amp;gt; the Google account swamps. We had a big team, lots of resources and even&lt;br/&gt;&amp;gt; just getting people to use their phone as a second factor - *the simplest&lt;br/&gt;&amp;gt; second factor possible* - was a huge uphill battle that most users just&lt;br/&gt;&amp;gt; didn&amp;#39;t care about. People like passwords. If you can find a way to make&lt;br/&gt;&amp;gt; something that&amp;#39;s better than a password but just as convenient, fantastic!&lt;br/&gt;&amp;gt; But I don&amp;#39;t think Bitcoin addresses are such a thing.&lt;br/&gt;&amp;gt;&lt;br/&gt;&lt;br/&gt;I perfectly understand all the objections, and they are very good points.&lt;br/&gt;&lt;br/&gt;I have at least two wallets enthousiastic about the project so the protocol&lt;br/&gt;will be implemented and it will give some room to experiment.&lt;br/&gt;The BIP came from the idea we should formalize the standard so all wallets&lt;br/&gt;could participate, and it felt more logical to come forward with it.&lt;br/&gt;&lt;br/&gt;Maybe a better strategy would be to start &amp;#34;privately&amp;#34; with a few wallets&lt;br/&gt;and services using the protocol, and to come back to the BIP there is&lt;br/&gt;usability and traction.&lt;br/&gt;&lt;br/&gt;Eric&lt;br/&gt;-------------- next part --------------&lt;br/&gt;An HTML attachment was scrubbed...&lt;br/&gt;URL: &amp;lt;&lt;a href=&#34;http://lists.linuxfoundation.org/pipermail/bitcoin-dev/attachments/20140404/c8740919/attachment.html&amp;gt&#34;&gt;http://lists.linuxfoundation.org/pipermail/bitcoin-dev/attachments/20140404/c8740919/attachment.html&amp;gt&lt;/a&gt;;
    </content>
    <updated>2023-06-07T15:17:22Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsgnafp3czq800hwk7g526dzys5vgdte0fykx6yxqegnjyew40jscczyq8ht7jt4ds4fk4s26ntgwsu2t4c8n3amy7wuv3exuy4ay5k5l9aw5gehxs</id>
    
      <title type="html">📅 Original date posted:2014-04-04 📝 Original message:&amp;gt; ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsgnafp3czq800hwk7g526dzys5vgdte0fykx6yxqegnjyew40jscczyq8ht7jt4ds4fk4s26ntgwsu2t4c8n3amy7wuv3exuy4ay5k5l9aw5gehxs" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsvydra4rlrg70dy92sjraax2t6wfwll6mw26myer7qhh55kz463aqjqmg2f&#39;&gt;nevent1q…mg2f&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;📅 Original date posted:2014-04-04&lt;br/&gt;📝 Original message:&amp;gt;&lt;br/&gt;&amp;gt; The goal of writing a BIP seems to be to get lots of different wallet&lt;br/&gt;&amp;gt; authors to write lots of code for you - but I *am* a wallet author, and I&lt;br/&gt;&amp;gt; don&amp;#39;t think that&amp;#39;s the right way to get traction with a new scheme.&lt;br/&gt;&amp;gt;&lt;br/&gt;&lt;br/&gt;I started without a BIP and the feedback I got is that I should to a BIP.&lt;br/&gt;We cannot write all the code for all the wallets ; this is after all a&lt;br/&gt;communauty project.&lt;br/&gt;However we have and we will propose bounties for each wallet to support&lt;br/&gt;natively the protocol.&lt;br/&gt;&lt;br/&gt;&lt;br/&gt;&amp;gt; For instance the TREZOR guys would have to support your new protocol&lt;br/&gt;&amp;gt; otherwise if I paid my hotel bill with my TREZOR I couldn&amp;#39;t open the door&lt;br/&gt;&amp;gt; when I got there! But they probably have better things to be doing right&lt;br/&gt;&amp;gt; now.&lt;br/&gt;&amp;gt;&lt;br/&gt;&lt;br/&gt;Yes you are right. But if the concept of authenticating yourself gets&lt;br/&gt;traction, they will probably do it.&lt;br/&gt;&lt;br/&gt;&lt;br/&gt;&amp;gt; The key difference between just generating a client certificate and using&lt;br/&gt;&amp;gt; a Bitcoin address is that the client certificate is something that is used&lt;br/&gt;&amp;gt; *specifically* for identification. It leaves no trace in the block chain,&lt;br/&gt;&amp;gt; so no weird privacy issues, it doesn&amp;#39;t matter how you manage your wallet,&lt;br/&gt;&amp;gt; and you don&amp;#39;t have to persuade lots of people to support your idea because&lt;br/&gt;&amp;gt; it was already done &amp;gt;10 years ago and basically every browser/web server&lt;br/&gt;&amp;gt; supports it.&lt;br/&gt;&amp;gt;&lt;br/&gt;&lt;br/&gt;My view on this is mainly about the UX and the fact everyone in Bitcoinland&lt;br/&gt;has a wallet.&lt;br/&gt;It&amp;#39;s a approach leveraging this fact, with the possibility to build&lt;br/&gt;interesting apps combining address auth and the blockchain.&lt;br/&gt;&lt;br/&gt;I understand the problems related to multisig, contracts etc,&lt;br/&gt;There is no such thing as a from address in a transaction, however many&lt;br/&gt;services still take first tx as the return address.&lt;br/&gt;People will always find way of building and doing stuff (cf the message in&lt;br/&gt;the blockchain debate).&lt;br/&gt;&lt;br/&gt;&lt;br/&gt;&amp;gt; Some reasons client certs aren&amp;#39;t more widely used boil down to:&lt;br/&gt;&amp;gt;&lt;br/&gt;&amp;gt;    1. People like passwords. In particular they like forgetting them and&lt;br/&gt;&amp;gt;    then having friendly people assist them to get it back. Client certs can&lt;br/&gt;&amp;gt;    support this use case, but only if apps are checking the identity in them&lt;br/&gt;&amp;gt;    and not the key.&lt;br/&gt;&amp;gt;    2. The UI for managing client certs in browsers is pretty horrible.&lt;br/&gt;&amp;gt;    There&amp;#39;s little incentive to improve it because of (1).&lt;br/&gt;&amp;gt;    3. Cross-device sync doesn&amp;#39;t work very well. Apple are starting to&lt;br/&gt;&amp;gt;    tackle this with their iCloud Keychain Sync service but then of course,&lt;br/&gt;&amp;gt;    Apple has all your keys and you may well just sign in to things with your&lt;br/&gt;&amp;gt;    Apple account (if it were to be supported). Cross-device sync where the&lt;br/&gt;&amp;gt;    server *doesn&amp;#39;t* get your keys is supported by Chrome for passwords,&lt;br/&gt;&amp;gt;    but not client certs, because (1)&lt;br/&gt;&amp;gt;&lt;br/&gt;&amp;gt; None of the above issues have any obvious fix lurking within Bitcoin.&lt;br/&gt;&amp;gt;&lt;br/&gt;&lt;br/&gt;There is also the benefit of revocation with certificate and central&lt;br/&gt;authority.&lt;br/&gt;&lt;br/&gt;But, again, you already have a wallet and a Bitcoin address.&lt;br/&gt;So if you add a simple auth protocol, people will use it at no cost.&lt;br/&gt;&lt;br/&gt;Eric&lt;br/&gt;-------------- next part --------------&lt;br/&gt;An HTML attachment was scrubbed...&lt;br/&gt;URL: &amp;lt;&lt;a href=&#34;http://lists.linuxfoundation.org/pipermail/bitcoin-dev/attachments/20140404/9e6d4ffc/attachment.html&amp;gt&#34;&gt;http://lists.linuxfoundation.org/pipermail/bitcoin-dev/attachments/20140404/9e6d4ffc/attachment.html&amp;gt&lt;/a&gt;;
    </content>
    <updated>2023-06-07T15:17:21Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsdl0dpugeahrmhhcg7ch9n65k0vd8769mcdfe0zzusvz5mmsz750szyq8ht7jt4ds4fk4s26ntgwsu2t4c8n3amy7wuv3exuy4ay5k5l9aw3020ht</id>
    
      <title type="html">📅 Original date posted:2014-04-04 📝 Original message:&amp;gt; ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsdl0dpugeahrmhhcg7ch9n65k0vd8769mcdfe0zzusvz5mmsz750szyq8ht7jt4ds4fk4s26ntgwsu2t4c8n3amy7wuv3exuy4ay5k5l9aw3020ht" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsxz76srva489qkvzwgd8gvg3k4c0aav3u48sl34fdnjqx6zju9keq26y96m&#39;&gt;nevent1q…y96m&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;📅 Original date posted:2014-04-04&lt;br/&gt;📝 Original message:&amp;gt; Using a bitcoin address repeatedly is something we&amp;#39;re trying to move away&lt;br/&gt;from.&lt;br/&gt;&lt;br/&gt;This is indeed a flaw of the proposed protocol. However it really depends&lt;br/&gt;in the end of the usage : you could use an auth just once, to redeem a good&lt;br/&gt;you paid, or multiple times if this makes a sense (mining pool app for&lt;br/&gt;instance).&lt;br/&gt;&lt;br/&gt;&amp;gt; And using a bitcoin address as a persistent identity key feels like the&lt;br/&gt;wrong direction to me.&lt;br/&gt;&lt;br/&gt;What would be really the difference between artificially create a&lt;br/&gt;certificate for identity and selecting one address for identity?&lt;br/&gt;&lt;br/&gt;&amp;gt; Better to use something like client certificates, the FIDO alliance&amp;#39;s&lt;br/&gt;(new!) specs:&lt;br/&gt;&amp;gt;   &lt;a href=&#34;http://fidoalliance.org/specifications/download&#34;&gt;http://fidoalliance.org/specifications/download&lt;/a&gt;&lt;br/&gt;&amp;gt; ... or Steve Gibson&amp;#39;s proposed SQRL system:&lt;br/&gt;&amp;gt;   &lt;a href=&#34;https://www.grc.com/sqrl/sqrl.htm&#34;&gt;https://www.grc.com/sqrl/sqrl.htm&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;The proposal is nothing more than sqrl scoped to Bitcoin keys.&lt;br/&gt;&lt;br/&gt;&amp;gt; If one of those systems gets critical mass and actually starts being&lt;br/&gt;successful, then I think it would make sense to specify a standard way of&lt;br/&gt;using a HD wallet&amp;#39;s deterministic seed to derive a key used for the FIDO or&lt;br/&gt;SQRL systems.&lt;br/&gt;&lt;br/&gt;This could be a very interesting approach. But I think the system which&lt;br/&gt;would get critical mass is the one which would be implemented into major&lt;br/&gt;Bitcoin wallets.&lt;br/&gt;&lt;br/&gt;Why adding another app or software when you already have all you need?&lt;br/&gt;&lt;br/&gt;&amp;gt;&lt;br/&gt;&amp;gt;&lt;br/&gt;&amp;gt;&lt;br/&gt;&amp;gt;&lt;br/&gt;&amp;gt; On Fri, Apr 4, 2014 at 9:22 AM, Eric Larchevêque &amp;lt;elarch at gmail.com&amp;gt; wrote:&lt;br/&gt;&amp;gt;&amp;gt;&lt;br/&gt;&amp;gt;&amp;gt; What I&amp;#39;m trying to achieve, is to have a very simple way of&lt;br/&gt;authenticating yourself with one Bitcoin address from your wallet.&lt;br/&gt;&amp;gt;&amp;gt; For most of the people using Bitcoin, their wallet is on their phone.&lt;br/&gt;&amp;gt;&amp;gt;&lt;br/&gt;&amp;gt;&amp;gt; The UX is clear and simple :&lt;br/&gt;&amp;gt;&amp;gt; 1. click on &amp;#34;connect with Bitcoin&amp;#34; (the audience is normal people)&lt;br/&gt;&amp;gt;&amp;gt; 2. flash the QRcode with your wallet (blockchain.info, mycelium, ...)&lt;br/&gt;&amp;gt;&amp;gt; 3. accept the authentication request (same style than OpenID or Facebook&lt;br/&gt;connect)&lt;br/&gt;&amp;gt;&amp;gt; 4. user is autologged and identified by the chosen Bitcoin public address&lt;br/&gt;&amp;gt;&amp;gt;&lt;br/&gt;&amp;gt;&amp;gt; It makes sense only if major wallets are supporting the protocol. If you&lt;br/&gt;need to install a plugin or download a third party software, no one will do&lt;br/&gt;it.&lt;br/&gt;&amp;gt;&amp;gt; I see only benefits for the entire ecosystem, and if I&amp;#39;m working on such&lt;br/&gt;a proposition it is because I really need this feature.&lt;br/&gt;&amp;gt;&amp;gt;&lt;br/&gt;&amp;gt;&amp;gt; Of course, it can be done without a BIP, I just need to convince wallet&lt;br/&gt;developpers one by one to implement the feature.&lt;br/&gt;&amp;gt;&amp;gt; But I thought it was much better to start the &amp;#34;official&amp;#34; way, so all&lt;br/&gt;wallet could easily find and implement the same authentication mechanism.&lt;br/&gt;&amp;gt;&amp;gt;&lt;br/&gt;&amp;gt;&amp;gt; &amp;gt;  Bitcoin and website authentication are unrelated problems&lt;br/&gt;&amp;gt;&amp;gt;&lt;br/&gt;&amp;gt;&amp;gt; I respectfully disagree. Many services require your Bitcoin address, and&lt;br/&gt;to do that they artificially request an email/password to store it.&lt;br/&gt;&amp;gt;&amp;gt; This is not about authentication as an identity (as &amp;#34;I&amp;#39;m Eric&lt;br/&gt;Larcheveque&amp;#34;), but as in &amp;#34;I&amp;#39;m proving to you that I control this address&amp;#34;.&lt;br/&gt;&amp;gt;&amp;gt;&lt;br/&gt;&amp;gt;&amp;gt; Without such a standard protocol, you could never envision a pure&lt;br/&gt;Bitcoin physical locker rental, or booking an hotel room via Bitcoin and&lt;br/&gt;opening the door through the paying address.&lt;br/&gt;&amp;gt;&amp;gt;&lt;br/&gt;&amp;gt;&amp;gt; Eric&lt;br/&gt;&amp;gt;&amp;gt;&lt;br/&gt;&amp;gt;&amp;gt;&lt;br/&gt;&amp;gt;&amp;gt;&lt;br/&gt;&amp;gt;&amp;gt; On Fri, Apr 4, 2014 at 3:08 PM, Mike Hearn &amp;lt;mike at plan99.net&amp;gt; wrote:&lt;br/&gt;&amp;gt;&amp;gt;&amp;gt;&lt;br/&gt;&amp;gt;&amp;gt;&amp;gt; This comes up every few months. I think the problem you are trying to&lt;br/&gt;solve is already solved by SSL client certificates, and if you want to help&lt;br/&gt;make them more widespread the programs you need to upgrade are web browsers&lt;br/&gt;and not Bitcoin wallets. There are certainly bits of infrastructure you&lt;br/&gt;could reuse here and there, like perhaps a TREZOR with a custom firmware&lt;br/&gt;extension for really advanced/keen users, but overall Bitcoin and website&lt;br/&gt;authentication are unrelated problems.&lt;br/&gt;&amp;gt;&amp;gt;&amp;gt;&lt;br/&gt;&amp;gt;&amp;gt;&amp;gt;&lt;br/&gt;&amp;gt;&amp;gt;&amp;gt; On Fri, Apr 4, 2014 at 2:15 PM, Eric Larchevêque &amp;lt;elarch at gmail.com&amp;gt;&lt;br/&gt;wrote:&lt;br/&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&lt;br/&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; Hello,&lt;br/&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&lt;br/&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; I&amp;#39;ve written a draft BIP description of an authentication protocol&lt;br/&gt;based on Bitcoin public address.&lt;br/&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&lt;br/&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; By authentication we mean to prove to a service/application that we&lt;br/&gt;control a specific Bitcoin address by signing a challenge, and that all&lt;br/&gt;related data and settings may securely be linked to our session.&lt;br/&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&lt;br/&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; The aim is to greatly facilitate sign ups and logins to services and&lt;br/&gt;applications, improving the Bitcoin ecosystem as a whole.&lt;br/&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&lt;br/&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; &lt;a href=&#34;https://github.com/bitid/bitid/blob/master/BIP_draft.md&#34;&gt;https://github.com/bitid/bitid/blob/master/BIP_draft.md&lt;/a&gt;&lt;br/&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&lt;br/&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; Demo website :&lt;br/&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; &lt;a href=&#34;http://bitid-demo.herokuapp.com/&#34;&gt;http://bitid-demo.herokuapp.com/&lt;/a&gt;&lt;br/&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&lt;br/&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; Classical password authentication is an insecure process that could be&lt;br/&gt;solved with public key cryptography. The problem is that it theoretically&lt;br/&gt;offloads a lot of complexity and responsibility on the user. Managing&lt;br/&gt;private keys securely is complex. However this complexity is already being&lt;br/&gt;addressed in the Bitcoin ecosystem. So doing public key authentication is&lt;br/&gt;practically a free lunch to bitcoiners.&lt;br/&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&lt;br/&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; I&amp;#39;ve formatted the protocol description as a BIP because this is the&lt;br/&gt;only way to have all major wallets implementing it, and because it&lt;br/&gt;completely fits in my opinion the BIP &amp;#34;process&amp;#34; category.&lt;br/&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&lt;br/&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; Please read it and let me know your thoughts and comments so we can&lt;br/&gt;improve on this draft.&lt;br/&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&lt;br/&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; Eric Larcheveque&lt;br/&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; elarch at gmail.com&lt;br/&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&lt;br/&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&lt;br/&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&lt;br/&gt;------------------------------------------------------------------------------&lt;br/&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&lt;br/&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; _______________________________________________&lt;br/&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; Bitcoin-development mailing list&lt;br/&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; Bitcoin-development at lists.sourceforge.net&lt;br/&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; &lt;a href=&#34;https://lists.sourceforge.net/lists/listinfo/bitcoin-development&#34;&gt;https://lists.sourceforge.net/lists/listinfo/bitcoin-development&lt;/a&gt;&lt;br/&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&lt;br/&gt;&amp;gt;&amp;gt;&amp;gt;&lt;br/&gt;&amp;gt;&amp;gt;&lt;br/&gt;&amp;gt;&amp;gt;&lt;br/&gt;&amp;gt;&amp;gt;&lt;br/&gt;------------------------------------------------------------------------------&lt;br/&gt;&amp;gt;&amp;gt;&lt;br/&gt;&amp;gt;&amp;gt; _______________________________________________&lt;br/&gt;&amp;gt;&amp;gt; Bitcoin-development mailing list&lt;br/&gt;&amp;gt;&amp;gt; Bitcoin-development at lists.sourceforge.net&lt;br/&gt;&amp;gt;&amp;gt; &lt;a href=&#34;https://lists.sourceforge.net/lists/listinfo/bitcoin-development&#34;&gt;https://lists.sourceforge.net/lists/listinfo/bitcoin-development&lt;/a&gt;&lt;br/&gt;&amp;gt;&amp;gt;&lt;br/&gt;&amp;gt;&lt;br/&gt;&amp;gt;&lt;br/&gt;&amp;gt;&lt;br/&gt;&amp;gt; --&lt;br/&gt;&amp;gt; --&lt;br/&gt;&amp;gt; Gavin Andresen&lt;br/&gt;-------------- next part --------------&lt;br/&gt;An HTML attachment was scrubbed...&lt;br/&gt;URL: &amp;lt;&lt;a href=&#34;http://lists.linuxfoundation.org/pipermail/bitcoin-dev/attachments/20140404/f2c5cf7a/attachment.html&amp;gt&#34;&gt;http://lists.linuxfoundation.org/pipermail/bitcoin-dev/attachments/20140404/f2c5cf7a/attachment.html&amp;gt&lt;/a&gt;;
    </content>
    <updated>2023-06-07T15:17:18Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsteyxjs28a73a57p98g6qpcmcu46hlredk00y95qsq05ugztpdgqqzyq8ht7jt4ds4fk4s26ntgwsu2t4c8n3amy7wuv3exuy4ay5k5l9awnmd8ya</id>
    
      <title type="html">📅 Original date posted:2014-04-04 📝 Original message:What ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsteyxjs28a73a57p98g6qpcmcu46hlredk00y95qsq05ugztpdgqqzyq8ht7jt4ds4fk4s26ntgwsu2t4c8n3amy7wuv3exuy4ay5k5l9awnmd8ya" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqs27q3kyjuujpttslrhghk7lvm22jn0rrtmk4ysqaf38pxgnfxd4csrj3g6a&#39;&gt;nevent1q…3g6a&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;📅 Original date posted:2014-04-04&lt;br/&gt;📝 Original message:What I&amp;#39;m trying to achieve, is to have a very simple way of authenticating&lt;br/&gt;yourself with one Bitcoin address from your wallet.&lt;br/&gt;For most of the people using Bitcoin, their wallet is on their phone.&lt;br/&gt;&lt;br/&gt;The UX is clear and simple :&lt;br/&gt;1. click on &amp;#34;connect with Bitcoin&amp;#34; (the audience is normal people)&lt;br/&gt;2. flash the QRcode with your wallet (blockchain.info, mycelium, ...)&lt;br/&gt;3. accept the authentication request (same style than OpenID or Facebook&lt;br/&gt;connect)&lt;br/&gt;4. user is autologged and identified by the chosen Bitcoin public address&lt;br/&gt;&lt;br/&gt;It makes sense only if major wallets are supporting the protocol. If you&lt;br/&gt;need to install a plugin or download a third party software, no one will do&lt;br/&gt;it.&lt;br/&gt;I see only benefits for the entire ecosystem, and if I&amp;#39;m working on such a&lt;br/&gt;proposition it is because I really need this feature.&lt;br/&gt;&lt;br/&gt;Of course, it can be done without a BIP, I just need to convince wallet&lt;br/&gt;developpers one by one to implement the feature.&lt;br/&gt;But I thought it was much better to start the &amp;#34;official&amp;#34; way, so all wallet&lt;br/&gt;could easily find and implement the same authentication mechanism.&lt;br/&gt;&lt;br/&gt;&amp;gt;  Bitcoin and website authentication are unrelated problems&lt;br/&gt;&lt;br/&gt;I respectfully disagree. Many services require your Bitcoin address, and to&lt;br/&gt;do that they artificially request an email/password to store it.&lt;br/&gt;This is not about authentication as an identity (as &amp;#34;I&amp;#39;m Eric&lt;br/&gt;Larcheveque&amp;#34;), but as in &amp;#34;I&amp;#39;m proving to you that I control this address&amp;#34;.&lt;br/&gt;&lt;br/&gt;Without such a standard protocol, you could never envision a pure Bitcoin&lt;br/&gt;physical locker rental, or booking an hotel room via Bitcoin and opening&lt;br/&gt;the door through the paying address.&lt;br/&gt;&lt;br/&gt;Eric&lt;br/&gt;&lt;br/&gt;&lt;br/&gt;&lt;br/&gt;On Fri, Apr 4, 2014 at 3:08 PM, Mike Hearn &amp;lt;mike at plan99.net&amp;gt; wrote:&lt;br/&gt;&lt;br/&gt;&amp;gt; This comes up every few months. I think the problem you are trying to&lt;br/&gt;&amp;gt; solve is already solved by SSL client certificates, and if you want to help&lt;br/&gt;&amp;gt; make them more widespread the programs you need to upgrade are web browsers&lt;br/&gt;&amp;gt; and not Bitcoin wallets. There are certainly bits of infrastructure you&lt;br/&gt;&amp;gt; could reuse here and there, like perhaps a TREZOR with a custom firmware&lt;br/&gt;&amp;gt; extension for really advanced/keen users, but overall Bitcoin and website&lt;br/&gt;&amp;gt; authentication are unrelated problems.&lt;br/&gt;&amp;gt;&lt;br/&gt;&amp;gt;&lt;br/&gt;&amp;gt; On Fri, Apr 4, 2014 at 2:15 PM, Eric Larchevêque &amp;lt;elarch at gmail.com&amp;gt; wrote:&lt;br/&gt;&amp;gt;&lt;br/&gt;&amp;gt;&amp;gt; Hello,&lt;br/&gt;&amp;gt;&amp;gt;&lt;br/&gt;&amp;gt;&amp;gt; I&amp;#39;ve written a draft BIP description of an authentication protocol based&lt;br/&gt;&amp;gt;&amp;gt; on Bitcoin public address.&lt;br/&gt;&amp;gt;&amp;gt;&lt;br/&gt;&amp;gt;&amp;gt; By authentication we mean to prove to a service/application that we&lt;br/&gt;&amp;gt;&amp;gt; control a specific Bitcoin address by signing a challenge, and that all&lt;br/&gt;&amp;gt;&amp;gt; related data and settings may securely be linked to our session.&lt;br/&gt;&amp;gt;&amp;gt;&lt;br/&gt;&amp;gt;&amp;gt; The aim is to greatly facilitate sign ups and logins to services and&lt;br/&gt;&amp;gt;&amp;gt; applications, improving the Bitcoin ecosystem as a whole.&lt;br/&gt;&amp;gt;&amp;gt;&lt;br/&gt;&amp;gt;&amp;gt; &lt;a href=&#34;https://github.com/bitid/bitid/blob/master/BIP_draft.md&#34;&gt;https://github.com/bitid/bitid/blob/master/BIP_draft.md&lt;/a&gt;&lt;br/&gt;&amp;gt;&amp;gt;&lt;br/&gt;&amp;gt;&amp;gt; Demo website :&lt;br/&gt;&amp;gt;&amp;gt; &lt;a href=&#34;http://bitid-demo.herokuapp.com/&#34;&gt;http://bitid-demo.herokuapp.com/&lt;/a&gt;&lt;br/&gt;&amp;gt;&amp;gt;&lt;br/&gt;&amp;gt;&amp;gt; Classical password authentication is an insecure process that could be&lt;br/&gt;&amp;gt;&amp;gt; solved with public key cryptography. The problem is that it theoretically&lt;br/&gt;&amp;gt;&amp;gt; offloads a lot of complexity and responsibility on the user. Managing&lt;br/&gt;&amp;gt;&amp;gt; private keys securely is complex. However this complexity is already being&lt;br/&gt;&amp;gt;&amp;gt; addressed in the Bitcoin ecosystem. So doing public key authentication is&lt;br/&gt;&amp;gt;&amp;gt; practically a free lunch to bitcoiners.&lt;br/&gt;&amp;gt;&amp;gt;&lt;br/&gt;&amp;gt;&amp;gt; I&amp;#39;ve formatted the protocol description as a BIP because this is the only&lt;br/&gt;&amp;gt;&amp;gt; way to have all major wallets implementing it, and because it completely&lt;br/&gt;&amp;gt;&amp;gt; fits in my opinion the BIP &amp;#34;process&amp;#34; category.&lt;br/&gt;&amp;gt;&amp;gt;&lt;br/&gt;&amp;gt;&amp;gt; Please read it and let me know your thoughts and comments so we can&lt;br/&gt;&amp;gt;&amp;gt; improve on this draft.&lt;br/&gt;&amp;gt;&amp;gt;&lt;br/&gt;&amp;gt;&amp;gt; Eric Larcheveque&lt;br/&gt;&amp;gt;&amp;gt; elarch at gmail.com&lt;br/&gt;&amp;gt;&amp;gt;&lt;br/&gt;&amp;gt;&amp;gt;&lt;br/&gt;&amp;gt;&amp;gt;&lt;br/&gt;&amp;gt;&amp;gt; ------------------------------------------------------------------------------&lt;br/&gt;&amp;gt;&amp;gt;&lt;br/&gt;&amp;gt;&amp;gt; _______________________________________________&lt;br/&gt;&amp;gt;&amp;gt; Bitcoin-development mailing list&lt;br/&gt;&amp;gt;&amp;gt; Bitcoin-development at lists.sourceforge.net&lt;br/&gt;&amp;gt;&amp;gt; &lt;a href=&#34;https://lists.sourceforge.net/lists/listinfo/bitcoin-development&#34;&gt;https://lists.sourceforge.net/lists/listinfo/bitcoin-development&lt;/a&gt;&lt;br/&gt;&amp;gt;&amp;gt;&lt;br/&gt;&amp;gt;&amp;gt;&lt;br/&gt;&amp;gt;&lt;br/&gt;-------------- next part --------------&lt;br/&gt;An HTML attachment was scrubbed...&lt;br/&gt;URL: &amp;lt;&lt;a href=&#34;http://lists.linuxfoundation.org/pipermail/bitcoin-dev/attachments/20140404/caca26c8/attachment.html&amp;gt&#34;&gt;http://lists.linuxfoundation.org/pipermail/bitcoin-dev/attachments/20140404/caca26c8/attachment.html&amp;gt&lt;/a&gt;;
    </content>
    <updated>2023-06-07T15:17:17Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsz2kr2cej3djm95rhscllm98ckjwvs6ltkq74vp49t2vr8qz2wjdqzyq8ht7jt4ds4fk4s26ntgwsu2t4c8n3amy7wuv3exuy4ay5k5l9awk0w7gf</id>
    
      <title type="html">📅 Original date posted:2014-04-04 📝 Original message:Hello, ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsz2kr2cej3djm95rhscllm98ckjwvs6ltkq74vp49t2vr8qz2wjdqzyq8ht7jt4ds4fk4s26ntgwsu2t4c8n3amy7wuv3exuy4ay5k5l9awk0w7gf" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsyaa4x8ycjrk2zsafq4uzxdruxlh3yr3uf5k6sduvw34ye6nfrrks7dc5m4&#39;&gt;nevent1q…c5m4&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;📅 Original date posted:2014-04-04&lt;br/&gt;📝 Original message:Hello,&lt;br/&gt;&lt;br/&gt;I&amp;#39;ve written a draft BIP description of an authentication protocol based on&lt;br/&gt;Bitcoin public address.&lt;br/&gt;&lt;br/&gt;By authentication we mean to prove to a service/application that we control&lt;br/&gt;a specific Bitcoin address by signing a challenge, and that all related&lt;br/&gt;data and settings may securely be linked to our session.&lt;br/&gt;&lt;br/&gt;The aim is to greatly facilitate sign ups and logins to services and&lt;br/&gt;applications, improving the Bitcoin ecosystem as a whole.&lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://github.com/bitid/bitid/blob/master/BIP_draft.md&#34;&gt;https://github.com/bitid/bitid/blob/master/BIP_draft.md&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;Demo website :&lt;br/&gt;&lt;a href=&#34;http://bitid-demo.herokuapp.com/&#34;&gt;http://bitid-demo.herokuapp.com/&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;Classical password authentication is an insecure process that could be&lt;br/&gt;solved with public key cryptography. The problem is that it theoretically&lt;br/&gt;offloads a lot of complexity and responsibility on the user. Managing&lt;br/&gt;private keys securely is complex. However this complexity is already being&lt;br/&gt;addressed in the Bitcoin ecosystem. So doing public key authentication is&lt;br/&gt;practically a free lunch to bitcoiners.&lt;br/&gt;&lt;br/&gt;I&amp;#39;ve formatted the protocol description as a BIP because this is the only&lt;br/&gt;way to have all major wallets implementing it, and because it completely&lt;br/&gt;fits in my opinion the BIP &amp;#34;process&amp;#34; category.&lt;br/&gt;&lt;br/&gt;Please read it and let me know your thoughts and comments so we can improve&lt;br/&gt;on this draft.&lt;br/&gt;&lt;br/&gt;Eric Larcheveque&lt;br/&gt;elarch at gmail.com&lt;br/&gt;-------------- next part --------------&lt;br/&gt;An HTML attachment was scrubbed...&lt;br/&gt;URL: &amp;lt;&lt;a href=&#34;http://lists.linuxfoundation.org/pipermail/bitcoin-dev/attachments/20140404/78771884/attachment.html&amp;gt&#34;&gt;http://lists.linuxfoundation.org/pipermail/bitcoin-dev/attachments/20140404/78771884/attachment.html&amp;gt&lt;/a&gt;;
    </content>
    <updated>2023-06-07T15:17:17Z</updated>
  </entry>

</feed>