<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom">
  <updated></updated>
  <generator>https://nostr.ae</generator>

  <title>Nostr notes by </title>
  <author>
    <name></name>
  </author>
  <link rel="self" type="application/atom+xml" href="https://nostr.ae/npub1trckpcxmceskq4cykxgwxm63n8ugrjrpu5mk83c90e4upsf7d9gqf0f95j.rss" />
  <link href="https://nostr.ae/npub1trckpcxmceskq4cykxgwxm63n8ugrjrpu5mk83c90e4upsf7d9gqf0f95j" />
  <id>https://nostr.ae/npub1trckpcxmceskq4cykxgwxm63n8ugrjrpu5mk83c90e4upsf7d9gqf0f95j</id>
  <icon></icon>
  <logo></logo>




  <entry>
    <id>https://nostr.ae/nevent1qqs8vjlr7jshx8q95haydduf6zn6uj4glc0rddfz5fzlkzgmcwfzgdqzypv0zc8qm0rxzczhqjcepcm02xvl3qwgv8jnwc78q4lxhsxp8e54qmv6057</id>
    
      <title type="html">📅 Original date posted:2015-06-23 📝 Original message:&amp;gt; ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqs8vjlr7jshx8q95haydduf6zn6uj4glc0rddfz5fzlkzgmcwfzgdqzypv0zc8qm0rxzczhqjcepcm02xvl3qwgv8jnwc78q4lxhsxp8e54qmv6057" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqs2ucwax2zzqgem743tu5pgen4t7p205hfevj0fkmxyzkuz85d3cqc5u5qw7&#39;&gt;nevent1q…5qw7&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;📅 Original date posted:2015-06-23&lt;br/&gt;📝 Original message:&amp;gt; Consensus is that this process is too painful to go through once a year.  I&lt;br/&gt;&amp;gt; agree.&lt;br/&gt;&amp;gt; &lt;br/&gt;&amp;gt; If you disagree and would like to see a Blocksize Council meet once a year&lt;br/&gt;&amp;gt; to issue a decree on what the maximum block size shall be for the next&lt;br/&gt;&amp;gt; year, then propose a process for who gets to sit on the Council and how&lt;br/&gt;&amp;gt; their decrees are enforced.....&lt;br/&gt;&lt;br/&gt;We could just as well say that the increases continue for 20 years, or&lt;br/&gt;until there is concensus to schedule a soft-fork to prevent further&lt;br/&gt;increase - whichever comes first.  That is the case already, of&lt;br/&gt;course, since there is no way to prevent a modest supermajority of&lt;br/&gt;miners from pushing through a soft-fork.  But explicitly accepting the&lt;br/&gt;possibility that the community might choose to cut the process short&lt;br/&gt;might make the BIP more palatable to some.&lt;br/&gt;&lt;br/&gt;It is also the reality: halting the blocksize increase before it hits&lt;br/&gt;the final 8GB limit is relatively easy, compared to the task of&lt;br/&gt;setting it in motion, so it does no real harm to set the &amp;#34;20 years&amp;#34;&lt;br/&gt;figure at the upper range of what we think is reasonable - even though&lt;br/&gt;under other circumstances one would probably say that extrapolating&lt;br/&gt;exponentials that far out would be foolhardy...&lt;br/&gt;&lt;br/&gt;roy
    </content>
    <updated>2023-06-07T15:39:48Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsq37ng6twpndpvyngq3hjcwzd7edgvulk66xe3rj5dg9pfkg46tqczypv0zc8qm0rxzczhqjcepcm02xvl3qwgv8jnwc78q4lxhsxp8e54q4k2v3l</id>
    
      <title type="html">📅 Original date posted:2015-02-05 📝 Original message:For ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsq37ng6twpndpvyngq3hjcwzd7edgvulk66xe3rj5dg9pfkg46tqczypv0zc8qm0rxzczhqjcepcm02xvl3qwgv8jnwc78q4lxhsxp8e54q4k2v3l" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsp064rgd0smtrp6z3qk7k6mas4xyq599a3tvrnyfg9wtntr546ursjfznpz&#39;&gt;nevent1q…znpz&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;📅 Original date posted:2015-02-05&lt;br/&gt;📝 Original message:For peer-to-peer payments, how common do we think that the payment is&lt;br/&gt;of an ad hoc nature rather than to a known contact?&lt;br/&gt;&lt;br/&gt;If I want to pay my friends/colleagues/etc over a restaurant table&lt;br/&gt;there&amp;#39;s no reason why I couldn&amp;#39;t already have their public keys in my&lt;br/&gt;contact list - then it would be pretty straightforward to have a&lt;br/&gt;watertight mechanism where I would know who I was paying.  You could&lt;br/&gt;probably even relatively securely bootstrap a key exchange over SMS,&lt;br/&gt;relying only on the contacts already having each other in their&lt;br/&gt;phonebooks.&lt;br/&gt;&lt;br/&gt;As for comsumer-to-merchant transactions where the merchant is a&lt;br/&gt;bricks and mortar merchant, IMHO it absolutely has to be &amp;#34;pay that&lt;br/&gt;terminal over there&amp;#34;.  It&amp;#39;s the trust model we all currently use -&lt;br/&gt;whether paying cash or card - and it&amp;#39;s the only trust model that works&lt;br/&gt;IMHO (and customers and businesses alike are well aware of the risks&lt;br/&gt;of a fraudster standing behind the counter pretending to be an&lt;br/&gt;employee accepting payment - and by and large are pretty good at&lt;br/&gt;mitigating it).  OTOH as we&amp;#39;ve discussed here before there are many&lt;br/&gt;use cases where the custoemr doesn&amp;#39;t actually know or care about the&lt;br/&gt;name of the shop or bar they walked into but is pretty damn sure that&lt;br/&gt;they need to make payment to the person over there behind the counter.&lt;br/&gt;&lt;br/&gt;Granted, there are cases taht dont&amp;#39; fall into either of the above -&lt;br/&gt;but they&amp;#39;re the cases that are (a) harder to figure out how to&lt;br/&gt;authenticate and consequently (b) the use cases that are going to be&lt;br/&gt;most subject to attempted fraud.&lt;br/&gt;&lt;br/&gt;roy&lt;br/&gt;&lt;br/&gt;On Thu, Feb 05, 2015 at 03:02:56PM -0800, William Swanson wrote:&lt;br/&gt;&amp;gt; On Thu, Feb 5, 2015 at 2:10 PM, Eric Voskuil &amp;lt;eric at voskuil.org&amp;gt; wrote:&lt;br/&gt;&amp;gt; &amp;gt; A MITM can receive the initial broadcast and then spoof it by jamming the&lt;br/&gt;&amp;gt; &amp;gt; original. You then only see one.&lt;br/&gt;&amp;gt; &lt;br/&gt;&amp;gt; You are right, of course. There is no way to make Bluetooth 100%&lt;br/&gt;&amp;gt; secure, since it is an over-the-air technology. You could try securing&lt;br/&gt;&amp;gt; it using a CA or other identity server, but now you&amp;#39;ve excluded ad-hoc&lt;br/&gt;&amp;gt; person-to-person payments. Plus, you need an active internet&lt;br/&gt;&amp;gt; connection to reach the CA.&lt;br/&gt;&amp;gt; &lt;br/&gt;&amp;gt; You can try using proximity as a substitute for identity, like&lt;br/&gt;&amp;gt; requiring NFC to kick-start the connection, but at that point you&lt;br/&gt;&amp;gt; might as well use QR codes.&lt;br/&gt;&amp;gt; &lt;br/&gt;&amp;gt; This BIP is not trying to provide absolute bullet-proof security,&lt;br/&gt;&amp;gt; since that&amp;#39;s impossible given the physical limitations of the&lt;br/&gt;&amp;gt; Bluetooth technology. Instead, it&amp;#39;s trying to provide the&lt;br/&gt;&amp;gt; best-possible security given those constraints. In exchange for this,&lt;br/&gt;&amp;gt; we get greatly enhanced usability in common scenarios.&lt;br/&gt;&amp;gt; &lt;br/&gt;&amp;gt; There are plenty of usable, real-world technologies with big security&lt;br/&gt;&amp;gt; holes. Anybody with lock-picking experience will tell you this, but&lt;br/&gt;&amp;gt; nobody is welding their front door shut. The ability to go in and out&lt;br/&gt;&amp;gt; is worth the security risk.&lt;br/&gt;&amp;gt; &lt;br/&gt;&amp;gt; Bluetooth payments add a whole new dimension to real-world Bitcoin&lt;br/&gt;&amp;gt; usability. Do we shut that down because it can&amp;#39;t be made perfect, or&lt;br/&gt;&amp;gt; do we do the best we can and move forward?&lt;br/&gt;&amp;gt; &lt;br/&gt;&amp;gt; -William&lt;br/&gt;&amp;gt; &lt;br/&gt;&amp;gt; ------------------------------------------------------------------------------&lt;br/&gt;&amp;gt; Dive into the World of Parallel Programming. The Go Parallel Website,&lt;br/&gt;&amp;gt; sponsored by Intel and developed in partnership with Slashdot Media, is your&lt;br/&gt;&amp;gt; hub for all things parallel software development, from weekly thought&lt;br/&gt;&amp;gt; leadership blogs to news, videos, case studies, tutorials and more. Take a&lt;br/&gt;&amp;gt; look and join the conversation now. &lt;a href=&#34;http://goparallel.sourceforge.net/&#34;&gt;http://goparallel.sourceforge.net/&lt;/a&gt;&lt;br/&gt;&amp;gt; _______________________________________________&lt;br/&gt;&amp;gt; Bitcoin-development mailing list&lt;br/&gt;&amp;gt; Bitcoin-development at lists.sourceforge.net&lt;br/&gt;&amp;gt; &lt;a href=&#34;https://lists.sourceforge.net/lists/listinfo/bitcoin-development&#34;&gt;https://lists.sourceforge.net/lists/listinfo/bitcoin-development&lt;/a&gt;&lt;br/&gt;&amp;gt;
    </content>
    <updated>2023-06-07T15:29:44Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqs8qeqyytlnyrgdfslk4642s5tcdj76wj78ujsjd7lmqpc2gkc3yqgzypv0zc8qm0rxzczhqjcepcm02xvl3qwgv8jnwc78q4lxhsxp8e54qtr4kgh</id>
    
      <title type="html">📅 Original date posted:2015-02-05 📝 Original ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqs8qeqyytlnyrgdfslk4642s5tcdj76wj78ujsjd7lmqpc2gkc3yqgzypv0zc8qm0rxzczhqjcepcm02xvl3qwgv8jnwc78q4lxhsxp8e54qtr4kgh" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqs8qtm0u22x7489ggwl0zcrjaugyjfs5dqfgxdfxxmma0h8k7klffcgvm3n5&#39;&gt;nevent1q…m3n5&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;📅 Original date posted:2015-02-05&lt;br/&gt;📝 Original message:Personally I like the simplicity of tapping two phones together to&lt;br/&gt;make payment - it should be quicker and easier than scanning QR codes&lt;br/&gt;and it&amp;#39;s a trust model that&amp;#39;s hard to misunderstand.&lt;br/&gt;&lt;br/&gt;Is NFC good enough for that?  I fear even with NFC it is possible to&lt;br/&gt;produce a device with longer range than one would expect.  What&lt;br/&gt;happened to the idea of tapping two devices together and then&lt;br/&gt;comparing the timing of the tap (as detected by the phones&amp;#39;&lt;br/&gt;accelerometers) to make spoofing a transaction harder?  I remember&lt;br/&gt;hearing about that years ago - is that still a thing?&lt;br/&gt;&lt;br/&gt;roy&lt;br/&gt;&lt;br/&gt;On Thu, Feb 05, 2015 at 02:10:51PM -0800, Eric Voskuil wrote:&lt;br/&gt;&amp;gt; A MITM can receive the initial broadcast and then spoof it by jamming the original. You then only see one.&lt;br/&gt;&amp;gt; &lt;br/&gt;&amp;gt; e&lt;br/&gt;&amp;gt; &lt;br/&gt;&amp;gt; &amp;gt; On Feb 5, 2015, at 2:07 PM, Paul Puey &amp;lt;paul at airbitz.co&amp;gt; wrote:&lt;br/&gt;&amp;gt; &amp;gt; &lt;br/&gt;&amp;gt; &amp;gt; So if you picked up the BLE broadcast request. All you know is that *someone* within 100m is requesting bitcoin at a certain address. Not necessarily who. The *name* is both optional, and possibly just a *handle* of the user. If I&amp;#39;m sitting 5 ft away from someone at dinner and wanted to pay them via BLE, I might see &amp;#34;Monkey Dude&amp;#34; on my list and simply ask him &amp;#34;is that you?&amp;#34; If so, I send it. If there are two &amp;#34;Monkey Dude&amp;#39;s&amp;#34; Then I have to bother with the address prefix, but not otherwise.&lt;br/&gt;&amp;gt; &amp;gt; &lt;br/&gt;&amp;gt; &amp;gt;&amp;gt; On Thu, Feb 5, 2015 at 1:46 PM, Eric Voskuil &amp;lt;eric at voskuil.org&amp;gt; wrote:&lt;br/&gt;&amp;gt; &amp;gt;&amp;gt; BLE has an advertised range of over 100m. &lt;br/&gt;&amp;gt; &amp;gt;&amp;gt; &lt;br/&gt;&amp;gt; &amp;gt;&amp;gt; &lt;a href=&#34;http://www.bluetooth.com/Pages/low-energy-tech-info.aspx&#34;&gt;http://www.bluetooth.com/Pages/low-energy-tech-info.aspx&lt;/a&gt;&lt;br/&gt;&amp;gt; &amp;gt;&amp;gt; &lt;br/&gt;&amp;gt; &amp;gt;&amp;gt; In the case of mass surveillance that range could most likely be extended dramatically by the reviewer. I&amp;#39;ve seen  WiFi ranges of over a mile with a strong (not FCC approved) receiver.&lt;br/&gt;&amp;gt; &amp;gt;&amp;gt; &lt;br/&gt;&amp;gt; &amp;gt;&amp;gt; WiFi hotspots don&amp;#39;t have strong identity or a guaranteed position, so they can&amp;#39;t be trusted for location.&lt;br/&gt;&amp;gt; &amp;gt;&amp;gt; &lt;br/&gt;&amp;gt; &amp;gt;&amp;gt; e&lt;br/&gt;&amp;gt; &amp;gt;&amp;gt; &lt;br/&gt;&amp;gt; &amp;gt;&amp;gt; On Feb 5, 2015, at 1:36 PM, Mike Hearn &amp;lt;mike at plan99.net&amp;gt; wrote:&lt;br/&gt;&amp;gt; &amp;gt;&amp;gt; &lt;br/&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;&amp;gt; This sounds horrible. You could basically monitor anyone with a wallet in a highly populated area and track them super easily by doing facial recognition.&lt;br/&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt; &lt;br/&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt; We&amp;#39;re talking about BLE, still? The radio tech that runs in the so called &amp;#34;junk bands&amp;#34; because propagation is so poor?&lt;br/&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt; &lt;br/&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt; My watch loses its connection to my phone if I just put it down and walk around my apartment. I&amp;#39;m all for reasonable paranoia, but Bluetooth isn&amp;#39;t going to be enabling mass surveillance any time soon. It barely goes through air, let alone walls.&lt;br/&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt; &lt;br/&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt; Anyway, whatever. I&amp;#39;m just bouncing around ideas for faster user interfaces. You could always switch it off or set it to be triggered by the presence of particular wifi hotspots, if you don&amp;#39;t mind an initial bit of setup.&lt;br/&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt; &lt;br/&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt; Back on topic - the debate is interesting, but I think to get this to the stage of being a BIP we&amp;#39;d need at least another wallet to implement it? Then I guess a BIP would be useful regardless of the design issues. The prefix matching still feels flaky to me but it&amp;#39;s hard to know if you could really swipe payments out of the air in practice, without actually trying it.&lt;br/&gt;&amp;gt; &amp;gt; &lt;br/&gt;&lt;br/&gt;&amp;gt; ------------------------------------------------------------------------------&lt;br/&gt;&amp;gt; Dive into the World of Parallel Programming. The Go Parallel Website,&lt;br/&gt;&amp;gt; sponsored by Intel and developed in partnership with Slashdot Media, is your&lt;br/&gt;&amp;gt; hub for all things parallel software development, from weekly thought&lt;br/&gt;&amp;gt; leadership blogs to news, videos, case studies, tutorials and more. Take a&lt;br/&gt;&amp;gt; look and join the conversation now. &lt;a href=&#34;http://goparallel.sourceforge.net/&#34;&gt;http://goparallel.sourceforge.net/&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;&amp;gt; _______________________________________________&lt;br/&gt;&amp;gt; Bitcoin-development mailing list&lt;br/&gt;&amp;gt; Bitcoin-development at lists.sourceforge.net&lt;br/&gt;&amp;gt; &lt;a href=&#34;https://lists.sourceforge.net/lists/listinfo/bitcoin-development&#34;&gt;https://lists.sourceforge.net/lists/listinfo/bitcoin-development&lt;/a&gt;
    </content>
    <updated>2023-06-07T15:29:43Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsdllnzt4qklxsgquu352zqrpmvq0qldxnw6635mepdwtysj37zykgzypv0zc8qm0rxzczhqjcepcm02xvl3qwgv8jnwc78q4lxhsxp8e54qe8k69s</id>
    
      <title type="html">📅 Original date posted:2014-03-29 📝 Original message:On ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsdllnzt4qklxsgquu352zqrpmvq0qldxnw6635mepdwtysj37zykgzypv0zc8qm0rxzczhqjcepcm02xvl3qwgv8jnwc78q4lxhsxp8e54qe8k69s" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsfc0px5e3sqag7w8wls062zar2vh6l25xylvx0je40f2uaenf5secgq49t2&#39;&gt;nevent1q…49t2&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;📅 Original date posted:2014-03-29&lt;br/&gt;📝 Original message:On Sat, Mar 29, 2014 at 01:42:01PM -0400, Matt Whitlock wrote:&lt;br/&gt;&amp;gt; On Saturday, 29 March 2014, at 5:28 pm, Roy Badami wrote:&lt;br/&gt;&amp;gt; &amp;gt; Right now there are also people simply taking base58-encoded private&lt;br/&gt;&amp;gt; &amp;gt; keys and running them through ssss-split.&lt;br/&gt;&amp;gt; &amp;gt; &lt;br/&gt;&amp;gt; &amp;gt; It has a lot going for it, since it can easily be reassembled on any&lt;br/&gt;&amp;gt; &amp;gt; Linux machine without special software (B Poettering&amp;#39;s Linux command&lt;br/&gt;&amp;gt; &amp;gt; line SSSS implementation[1] seems to be included in most Linux distros).&lt;br/&gt;&amp;gt; &amp;gt; &lt;br/&gt;&amp;gt; &amp;gt; roy&lt;br/&gt;&amp;gt; &amp;gt; &lt;br/&gt;&amp;gt; &amp;gt; [1] &lt;a href=&#34;http://point-at-infinity.org/ssss/&#34;&gt;http://point-at-infinity.org/ssss/&lt;/a&gt;&lt;br/&gt;&amp;gt; &lt;br/&gt;&amp;gt; Respectfully, it&amp;#39;s also possible to take a base58-encoded private key and run it through GPG, which is included in most Linux distros. But yet we have BIP38.&lt;br/&gt;&lt;br/&gt;And yet, how many wallets can import BIP38 keys?  If someone gave me&lt;br/&gt;one I would have no idea what software (if any) can understand it (nor&lt;br/&gt;would I have any idea how to generate one in the first place).&lt;br/&gt;&lt;br/&gt;Anyway, I&amp;#39;m not arguing against standardising these things - if people&lt;br/&gt;are going to implement this then of course it&amp;#39;s beneficial that they&lt;br/&gt;implement it compatibly.  It was just a simple observation - make of&lt;br/&gt;it what you will.&lt;br/&gt;&lt;br/&gt;roy
    </content>
    <updated>2023-06-07T15:16:42Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqszdt62s2dl6gvyhmejh98ymd9dfw42um3ny5pn8vrrz6nlev5ql4gzypv0zc8qm0rxzczhqjcepcm02xvl3qwgv8jnwc78q4lxhsxp8e54qma3k6z</id>
    
      <title type="html">📅 Original date posted:2014-03-29 📝 Original message:Right ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqszdt62s2dl6gvyhmejh98ymd9dfw42um3ny5pn8vrrz6nlev5ql4gzypv0zc8qm0rxzczhqjcepcm02xvl3qwgv8jnwc78q4lxhsxp8e54qma3k6z" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsgsqlactr0k6286pce389k879e2rgf0r2zg46w0xnyu5ugn596haczvv37h&#39;&gt;nevent1q…v37h&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;📅 Original date posted:2014-03-29&lt;br/&gt;📝 Original message:Right now there are also people simply taking base58-encoded private&lt;br/&gt;keys and running them through ssss-split.&lt;br/&gt;&lt;br/&gt;It has a lot going for it, since it can easily be reassembled on any&lt;br/&gt;Linux machine without special software (B Poettering&amp;#39;s Linux command&lt;br/&gt;line SSSS implementation[1] seems to be included in most Linux distros).&lt;br/&gt;&lt;br/&gt;roy&lt;br/&gt;&lt;br/&gt;[1] &lt;a href=&#34;http://point-at-infinity.org/ssss/&#34;&gt;http://point-at-infinity.org/ssss/&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;On Sat, Mar 29, 2014 at 12:59:19PM -0400, Alan Reiner wrote:&lt;br/&gt;&amp;gt; &lt;br/&gt;&amp;gt; Armory has had &amp;#34;Fragmented Backups&amp;#34; for over a year, now.  Advanced&lt;br/&gt;&amp;gt; users love it.  Though, I would say it&amp;#39;s kind of difficult to&lt;br/&gt;&amp;gt; standardize the way I did it since I was able to implement all the&lt;br/&gt;&amp;gt; finite field math with recursion, list comprehensions and python&lt;br/&gt;&amp;gt; arbitrary-big-integers in about 100 lines.  I&amp;#39;m not sure how &amp;#34;portable&amp;#34;&lt;br/&gt;&amp;gt; it is to other languages.  There&amp;#39;s obviously better ways to do it, but I&lt;br/&gt;&amp;gt; didn&amp;#39;t need a better way, because I don&amp;#39;t need to support fragmentation&lt;br/&gt;&amp;gt; above M=8 and this was 100% sufficient for it.  And I was the only one&lt;br/&gt;&amp;gt; doing it, so there was no one to be compatible with.&lt;br/&gt;&amp;gt; &lt;br/&gt;&amp;gt; I won&amp;#39;t lie, there&amp;#39;s a lot of work that goes into making an interface&lt;br/&gt;&amp;gt; that makes this feature &amp;#34;usable.&amp;#34;  The user needs clear ways to identify&lt;br/&gt;&amp;gt; which fragments are associated with which wallet, and which fragments&lt;br/&gt;&amp;gt; are compatible with each other.  They need a way to save some fragments&lt;br/&gt;&amp;gt; to file, print them, or simply write them down.  They need a way to&lt;br/&gt;&amp;gt; re-enter fragment, reject duplicates, identify errors, etc.  Without it,&lt;br/&gt;&amp;gt; the math fails silently, and you end up restoring a different wallet.   &lt;br/&gt;&amp;gt; And they need a way to test that it all works.   Armory did all this,&lt;br/&gt;&amp;gt; but it was no trivial task.  Including an interface that will test up to&lt;br/&gt;&amp;gt; 50 subsets of make sure the math produces the same values every time&lt;br/&gt;&amp;gt; (which still is not sufficient for some users, who won&amp;#39;t be satisified&lt;br/&gt;&amp;gt; til they see they&amp;#39;re wallet actually restored from fragments.&lt;br/&gt;&amp;gt; &lt;br/&gt;&amp;gt; Also I put the secret in the highest-order coefficient of the&lt;br/&gt;&amp;gt; polynomial, and made sure that the other coefficients were&lt;br/&gt;&amp;gt; deterministic.  This meant that if print out an M-of-N wallet, I can&lt;br/&gt;&amp;gt; later print out an M-of-(N&#43;1) wallet and the first N fragments will be&lt;br/&gt;&amp;gt; the same.  I&amp;#39;m not sure how many users would trust this, but we felt it&lt;br/&gt;&amp;gt; was important in case a user needs to export some fragments, even if&lt;br/&gt;&amp;gt; they don&amp;#39;t increase N.&lt;br/&gt;&amp;gt; &lt;br/&gt;&amp;gt; You might consider loading Armory in offline mode, create a wallet, and&lt;br/&gt;&amp;gt; then do a fragmented backup to see how we did it.  I am extremely&lt;br/&gt;&amp;gt; satisfied with the interface, but it&amp;#39;s most definitely an &amp;#34;advanced&amp;#34;&lt;br/&gt;&amp;gt; tool.  But so is Armory ... which made it a good fit.  But it might not&lt;br/&gt;&amp;gt; be for everyone.&lt;br/&gt;&amp;gt; &lt;br/&gt;&amp;gt; -Alan&lt;br/&gt;&amp;gt; &lt;br/&gt;&amp;gt; &lt;br/&gt;&amp;gt; &lt;br/&gt;&amp;gt; On 03/29/2014 11:44 AM, Matt Whitlock wrote:&lt;br/&gt;&amp;gt; &amp;gt; On Saturday, 29 March 2014, at 11:08 am, Watson Ladd wrote:&lt;br/&gt;&amp;gt; &amp;gt;&amp;gt; &lt;a href=&#34;https://freedom-to-tinker.com/blog/stevenag/new-research-better-wallet-security-for-bitcoin/&#34;&gt;https://freedom-to-tinker.com/blog/stevenag/new-research-better-wallet-security-for-bitcoin/&lt;/a&gt;&lt;br/&gt;&amp;gt; &amp;gt; Thanks. This is great, although it makes some critical references to an ACM paper for which no URL is provided, and thus I cannot implement it.&lt;br/&gt;&amp;gt; &amp;gt;&lt;br/&gt;&amp;gt; &amp;gt; A distributed ECDSA notwithstanding, we still need a way to decompose a BIP32 master seed into shares. I am envisioning a scenario in which I might meet my sudden and untimely demise, and I wish to allow my beneficiaries to reconstruct my wallet&amp;#39;s master seed after my death. I would like to distribute seed shares to each of my beneficiaries and some close friends, such that some subset of the shares must be joined together to reconstitute my master seed. Shamir&amp;#39;s Secret Sharing Scheme is perfect for this use case. I am presently working on extending my draft BIP so that it also applies to BIP32 master seeds of various sizes.&lt;br/&gt;&amp;gt; &amp;gt;&lt;br/&gt;&amp;gt; &amp;gt; ------------------------------------------------------------------------------&lt;br/&gt;&amp;gt; &amp;gt; _______________________________________________&lt;br/&gt;&amp;gt; &amp;gt; Bitcoin-development mailing list&lt;br/&gt;&amp;gt; &amp;gt; Bitcoin-development at lists.sourceforge.net&lt;br/&gt;&amp;gt; &amp;gt; &lt;a href=&#34;https://lists.sourceforge.net/lists/listinfo/bitcoin-development&#34;&gt;https://lists.sourceforge.net/lists/listinfo/bitcoin-development&lt;/a&gt;&lt;br/&gt;&amp;gt; &lt;br/&gt;&amp;gt; &lt;br/&gt;&amp;gt; ------------------------------------------------------------------------------&lt;br/&gt;&amp;gt; _______________________________________________&lt;br/&gt;&amp;gt; Bitcoin-development mailing list&lt;br/&gt;&amp;gt; Bitcoin-development at lists.sourceforge.net&lt;br/&gt;&amp;gt; &lt;a href=&#34;https://lists.sourceforge.net/lists/listinfo/bitcoin-development&#34;&gt;https://lists.sourceforge.net/lists/listinfo/bitcoin-development&lt;/a&gt;&lt;br/&gt;&amp;gt;
    </content>
    <updated>2023-06-07T15:16:42Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsg9zphrq0gwn96x69sv04amyvdwz0etxnl3qkm4hlljxnh798ykcszypv0zc8qm0rxzczhqjcepcm02xvl3qwgv8jnwc78q4lxhsxp8e54q2fz639</id>
    
      <title type="html">📅 Original date posted:2014-03-14 📝 Original message:On ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsg9zphrq0gwn96x69sv04amyvdwz0etxnl3qkm4hlljxnh798ykcszypv0zc8qm0rxzczhqjcepcm02xvl3qwgv8jnwc78q4lxhsxp8e54q2fz639" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsgq5v5tdg2c92xjuhk0mqamscgxr2xpxc57vmxfhfj7ust59n3rpcywchpu&#39;&gt;nevent1q…chpu&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;📅 Original date posted:2014-03-14&lt;br/&gt;📝 Original message:On Fri, Mar 14, 2014 at 03:05:25PM &#43;0100, Andreas Schildbach wrote:&lt;br/&gt;&amp;gt; btw. None of Bitcoin Wallet&amp;#39;s users complained about confusion because&lt;br/&gt;&amp;gt; of the mBTC switch. In contrast, I get many mails and questions if&lt;br/&gt;&amp;gt; exchange rates happen to differ by &amp;gt;10%.&lt;br/&gt;&lt;br/&gt;At the moment, I imagine the vast majority of Bitcoin users are&lt;br/&gt;familliar with SI units and know what milli- and micro- mean.&lt;br/&gt;&lt;br/&gt;I doubt that is true of the general population, though.&lt;br/&gt;&lt;br/&gt;roy
    </content>
    <updated>2023-06-07T15:15:31Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqswn98x0fypz2tzm34fzjwjr68su03cqnea5t9a0fyakmj2nkmdl0szypv0zc8qm0rxzczhqjcepcm02xvl3qwgv8jnwc78q4lxhsxp8e54qvkptgv</id>
    
      <title type="html">📅 Original date posted:2014-03-20 📝 Original message:On ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqswn98x0fypz2tzm34fzjwjr68su03cqnea5t9a0fyakmj2nkmdl0szypv0zc8qm0rxzczhqjcepcm02xvl3qwgv8jnwc78q4lxhsxp8e54qvkptgv" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqst59vfzrg97kwd6z2lhpav32vepxz9jmxxrf6wn0ynyhu0zr4zsvgqepcsm&#39;&gt;nevent1q…pcsm&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;📅 Original date posted:2014-03-20&lt;br/&gt;📝 Original message:On Thu, Mar 20, 2014 at 07:31:27PM &#43;0100, Mike Hearn wrote:&lt;br/&gt;&lt;br/&gt;&amp;gt; Yes, this overlaps somewhat with the PKI signing in BIP70, but not&lt;br/&gt;&amp;gt; entirely - you might want to serve unsigned payment requests, but&lt;br/&gt;&amp;gt; still have confidentiality and authenticity for a local face to face&lt;br/&gt;&amp;gt; transaction. The signing and encryption does different things&lt;br/&gt;&lt;br/&gt;I&amp;#39;m not sure if this what you&amp;#39;re getting at, but in a common&lt;br/&gt;face-to-face scenario, it really doesn&amp;#39;t overlap so much (in that the&lt;br/&gt;PKI in BIP70 isn&amp;#39;t really helpful).&lt;br/&gt;&lt;br/&gt;It&amp;#39;s not unusual, in a face-to-face transaction at a bricks-and-mortar&lt;br/&gt;establishment, that you know neither the legal name of the entity&lt;br/&gt;running the establishment, nor any electronic identifier (domain name,&lt;br/&gt;email address) that might be presented to you in an X.509 certificate,&lt;br/&gt;even if such a certificate is presented in the PaymentRequest.&lt;br/&gt;&lt;br/&gt;In many cases I want/need to simply be assured that I am paying &amp;#34;the&lt;br/&gt;person/organisation which operates that machine behind the counter,&lt;br/&gt;right there&amp;#34;.&lt;br/&gt;&lt;br/&gt;In many ways I&amp;#39;ll miss the simplicity of BIP21 QR codes for&lt;br/&gt;face-to-face transactions - because in this use case the payment&lt;br/&gt;protocol complicates (and in many cases weakens) the assurance that&lt;br/&gt;you really are paying the entity that prepared the QR code.&lt;br/&gt;&lt;br/&gt;roy
    </content>
    <updated>2023-06-07T15:14:25Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqspkqluyszfhml9g27zgehsc55l46m522y35pwmerf37w7qsgvtz8czypv0zc8qm0rxzczhqjcepcm02xvl3qwgv8jnwc78q4lxhsxp8e54qk9a9tj</id>
    
      <title type="html">📅 Original date posted:2014-03-26 📝 Original message:On ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqspkqluyszfhml9g27zgehsc55l46m522y35pwmerf37w7qsgvtz8czypv0zc8qm0rxzczhqjcepcm02xvl3qwgv8jnwc78q4lxhsxp8e54qk9a9tj" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqstfudulgnhlk9jeerj3e2pkpvdtnqf5cjt2hjzrh0z5uvgelm99fgxwrsfh&#39;&gt;nevent1q…rsfh&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;📅 Original date posted:2014-03-26&lt;br/&gt;📝 Original message:On Fri, Mar 21, 2014 at 12:02:44AM &#43;0100, Mike Hearn wrote:&lt;br/&gt;&amp;gt; &amp;gt;&lt;br/&gt;&amp;gt; &amp;gt; It&amp;#39;s not unusual, in a face-to-face transaction at a bricks-and-mortar&lt;br/&gt;&amp;gt; &amp;gt; establishment, that you know neither the legal name of the entity&lt;br/&gt;&amp;gt; &amp;gt; running the establishment&lt;br/&gt;&amp;gt; &lt;br/&gt;&amp;gt; &lt;br/&gt;&amp;gt; I&amp;#39;d hope that people can get certs for their actual business name, but&lt;br/&gt;&amp;gt; sometimes it does differ yes.&lt;br/&gt;&lt;br/&gt;The actual example I was thinking of is that of traditional British&lt;br/&gt;pubs.  Often a company will own several pubs - however the pubs&lt;br/&gt;themselves will typically have individual traditional pub names.  The&lt;br/&gt;name of the company might not be at all prominently advertised in the&lt;br/&gt;pubs.&lt;br/&gt;&lt;br/&gt;Traders at music festivals are another example that comes to mind (they&lt;br/&gt;often accept credit cards if they sell higher value items so why not&lt;br/&gt;Bitcoin?)  In this example there often are no clearly advertised&lt;br/&gt;business names - at least, that the customer will be aware of.&lt;br/&gt;&lt;br/&gt;roy
    </content>
    <updated>2023-06-07T15:14:25Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsttrt807f5szys2yhnat72zdt2qux430evc99rfrqxk8ur8pgm07qzypv0zc8qm0rxzczhqjcepcm02xvl3qwgv8jnwc78q4lxhsxp8e54qgmj2z5</id>
    
      <title type="html">📅 Original date posted:2014-01-27 📝 Original message:On ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsttrt807f5szys2yhnat72zdt2qux430evc99rfrqxk8ur8pgm07qzypv0zc8qm0rxzczhqjcepcm02xvl3qwgv8jnwc78q4lxhsxp8e54qgmj2z5" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsxku0yhy7z5qqgdas9etu4e7whwg0p0x7shsa9dnafq42zr75k0mqxs2622&#39;&gt;nevent1q…2622&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;📅 Original date posted:2014-01-27&lt;br/&gt;📝 Original message:On Mon, Jan 27, 2014 at 09:11:08AM -0800, Jeremy Spilman wrote:&lt;br/&gt;&amp;gt; On Mon, 27 Jan 2014 03:59:25 -0800, Andreas Schildbach  &lt;br/&gt;&amp;gt; &amp;lt;andreas at schildbach.de&amp;gt; wrote:&lt;br/&gt;&amp;gt; &lt;br/&gt;&amp;gt; &amp;gt; SCAN TO PAY&lt;br/&gt;&amp;gt; &amp;gt; For scan-to-pay, the current landscape looks different. I assume at&lt;br/&gt;&amp;gt; &amp;gt; least 50% of Bitcoin transactions are initiated by a BIP21 URL encoded&lt;br/&gt;&amp;gt; &amp;gt; into a QR-code. Nevertheless, I tried to encode a payment request into&lt;br/&gt;&amp;gt; &amp;gt; the bitcoin URL. I used my existing work on encoding transactions into&lt;br/&gt;&amp;gt; &amp;gt; QR-codes. Steps to encode:&lt;br/&gt;&amp;gt; &lt;br/&gt;&amp;gt; Really interesting work. When using scan-to-pay, after the payer scans the  &lt;br/&gt;&amp;gt; QR code with the protobuf PaymentRequest (not a URL to download the  &lt;br/&gt;&amp;gt; PaymentRequest) are they using their own connectivity to submit the  &lt;br/&gt;&amp;gt; Payment response?&lt;br/&gt;&amp;gt; &lt;br/&gt;&amp;gt; If we assume connectivity on the phone, might as well just get a URL from  &lt;br/&gt;&amp;gt; the QR code and re-use existing infrastructure for serving that?&lt;br/&gt;&lt;br/&gt;My first thought was likewise.  In the case where the phone needs&lt;br/&gt;Internet connectivity anyway, why not include an HTTPS URL in a BIP 72 URL?&lt;br/&gt;&lt;br/&gt;I&amp;#39;m assuming that every client will have to support this is any case,&lt;br/&gt;since it&amp;#39;s effectively mandated by the BIP, so why add another mode of&lt;br/&gt;operation?&lt;br/&gt;&lt;br/&gt;However, PaymentRequest-over-QR-code does seem to me to have one&lt;br/&gt;rather attractive advantage: the authentication model is orders of&lt;br/&gt;magnitude simpler and more intuitive for a face-to-face transaction&lt;br/&gt;than anything else.  You&amp;#39;re saying &amp;#34;pay the coins to that thing over&lt;br/&gt;there displaying that QR code&amp;#34;.  Which, most of the time, is exactly&lt;br/&gt;what you want.&lt;br/&gt;&lt;br/&gt;In the web case, it&amp;#39;s fine to ignore the case where the URL domain has&lt;br/&gt;been subverted (and an cert obtained by the attacker) because in that&lt;br/&gt;case you&amp;#39;ve lost before you even get to payments (MitM attacker shows&lt;br/&gt;you a modified web page with different payment details).  But the&lt;br/&gt;face-to-face case isn&amp;#39;t intrinsically dependent on SSL security, and&lt;br/&gt;it&amp;#39;s nice not to introduce that attack vector...&lt;br/&gt;&lt;br/&gt;roy
    </content>
    <updated>2023-06-07T15:12:43Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsv60cetluwzaf7x3gh5st4mljjas84vxa8pdsy4rz5gl2ay766zcszypv0zc8qm0rxzczhqjcepcm02xvl3qwgv8jnwc78q4lxhsxp8e54qpeavsh</id>
    
      <title type="html">📅 Original date posted:2014-01-13 📝 Original message:&amp;gt; ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsv60cetluwzaf7x3gh5st4mljjas84vxa8pdsy4rz5gl2ay766zcszypv0zc8qm0rxzczhqjcepcm02xvl3qwgv8jnwc78q4lxhsxp8e54qpeavsh" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqswmns7gqhlhnzsnyqzaxfymqklmlxqkt3fulq5jzta34yn838khsc5zeas3&#39;&gt;nevent1q…eas3&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;📅 Original date posted:2014-01-13&lt;br/&gt;📝 Original message:&amp;gt; It&amp;#39;s not public.  When I say &amp;#34;please pay me&amp;#34; I also say &amp;#34;use this&lt;br/&gt;&amp;gt; multiplier&amp;#34;.&lt;br/&gt;&lt;br/&gt;Sending a &amp;#34;please pay me&amp;#34; message is really great for business&lt;br/&gt;transactions.&lt;br/&gt;&lt;br/&gt;But I think the use case that Peter Todd mentions is actually *the*&lt;br/&gt;most important currently under-addresesd use case:&lt;br/&gt;&lt;br/&gt;&amp;gt; With stealth addresses the user experience can be as simple as you&lt;br/&gt;&amp;gt; telling me on the phone &amp;#34;hey! send me that 0.234 BTC you owe me!&amp;#34;,&lt;br/&gt;&amp;gt; me clicking on &amp;#34;Send to Alan Reiner (verified by PGP)&amp;#34; (perhaps&lt;br/&gt;&amp;gt; again on my off-line second factor device for a multi-sig wallet)&lt;br/&gt;&amp;gt; and tellling you &amp;#34;OK, sent&amp;#34;.&lt;br/&gt;&lt;br/&gt;Lots of work is being done on handling consumer-to-merchant&lt;br/&gt;transactions.  BIP 70 does a good job of tackling the online purchase&lt;br/&gt;case, and the work that Andreas Schildbach is doing with Bluetooth and&lt;br/&gt;NFC will improve the options for a payer in a physical PoS transaction&lt;br/&gt;who might not have Internet connectivity on their smartphone.&lt;br/&gt;&lt;br/&gt;But relatively little work (that I know of) is being done on&lt;br/&gt;non-transactional personal payments - that is, being able to pay money&lt;br/&gt;to friends and other people that you have a face-to-face relationship&lt;br/&gt;with.&lt;br/&gt;&lt;br/&gt;What I want... no need... is to be able to open my wallet, select a&lt;br/&gt;friend from my address book, and transfer the $10 I owe them from the&lt;br/&gt;bar last night.&lt;br/&gt;&lt;br/&gt;I don&amp;#39;t care - within reason - what process is involved in getting my&lt;br/&gt;friend set up in my address book.  That may well requires two way&lt;br/&gt;communication (e.g. over NFC).  But once it&amp;#39;s set up, I should be able&lt;br/&gt;to just select the payee from the address book and send them some&lt;br/&gt;funds.  Anything else is just too complciated.&lt;br/&gt;&lt;br/&gt;I don&amp;#39;t know if stealth addresses are the best solution to address&lt;br/&gt;this use case, but AFAIK the only current solution to this use case is&lt;br/&gt;to store a long-lived Bitcoin address in the addresss book.&lt;br/&gt;&lt;br/&gt;roy
    </content>
    <updated>2023-06-07T15:11:55Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqst8ma5j8zjyv7fxdt8zwjjz228jch6gvnlxgv9cwgry2a7tlk8a5gzypv0zc8qm0rxzczhqjcepcm02xvl3qwgv8jnwc78q4lxhsxp8e54q393a64</id>
    
      <title type="html">📅 Original date posted:2014-01-13 📝 Original message:On ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqst8ma5j8zjyv7fxdt8zwjjz228jch6gvnlxgv9cwgry2a7tlk8a5gzypv0zc8qm0rxzczhqjcepcm02xvl3qwgv8jnwc78q4lxhsxp8e54q393a64" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsr2r63ug8tncpm3h9s7zfyku5042xcatj6yskukmn3y2gurytukuc564hp9&#39;&gt;nevent1q…4hp9&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;📅 Original date posted:2014-01-13&lt;br/&gt;📝 Original message:On Mon, Jan 13, 2014 at 01:52:25AM -0800, Gregory Maxwell wrote:&lt;br/&gt;&amp;gt; On Sun, Jan 12, 2014 at 1:18 PM, Gavin Andresen &amp;lt;gavinandresen at gmail.com&amp;gt; wrote:&lt;br/&gt;&amp;gt; &amp;gt; No, please. Make it easy for non-geeks, extend the payment protocol, or&lt;br/&gt;&amp;gt; &amp;gt; we&amp;#39;ll spend the next two years writing code that tries to ignore linebreaks&lt;br/&gt;&amp;gt; &amp;gt; and spaces and changing &amp;lt;input&amp;gt; elements in HTML forms to &amp;lt;textarea&amp;gt; ....&lt;br/&gt;&amp;gt; &lt;br/&gt;&amp;gt; However, if you&amp;#39;re able to use the payment protocol then you probably&lt;br/&gt;&amp;gt; don&amp;#39;t need stealth addresses to prevent reuse.&lt;br/&gt;&lt;br/&gt;I definitely think this is a case that should be addressed better than&lt;br/&gt;at present.&lt;br/&gt;&lt;br/&gt;To consider a concrete use case, imagine I wish to be able to give my&lt;br/&gt;friends and acquaintances a paper business card with a QR code on it,&lt;br/&gt;that they can use to make payments to me.  I don&amp;#39;t own a domain or any&lt;br/&gt;kind of X.509 certificate and I don&amp;#39;t run an HTTP server.  I don&amp;#39;t&lt;br/&gt;feel comfortable with a solution that requires me to trust a third&lt;br/&gt;party to complete the payments.&lt;br/&gt;&lt;br/&gt;At the moment, I can give them a business card with a Bitcoin address.&lt;br/&gt;Being able to give out a business card with a stealth address would be&lt;br/&gt;a major advance.&lt;br/&gt;&lt;br/&gt;roy
    </content>
    <updated>2023-06-07T15:11:51Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqs9zy9alsp8d0gp2c6v72g7u66r8t8r6mwpqpfglzps0xd6zcwlq4czypv0zc8qm0rxzczhqjcepcm02xvl3qwgv8jnwc78q4lxhsxp8e54q7yu0e7</id>
    
      <title type="html">📅 Original date posted:2014-01-13 📝 Original message:&amp;gt; ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqs9zy9alsp8d0gp2c6v72g7u66r8t8r6mwpqpfglzps0xd6zcwlq4czypv0zc8qm0rxzczhqjcepcm02xvl3qwgv8jnwc78q4lxhsxp8e54q7yu0e7" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqs94dh4a9zapwnyr7m05uv582sxm9tsp6uapugmzn5jkxxj2q8mlng78hx3a&#39;&gt;nevent1q…hx3a&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;📅 Original date posted:2014-01-13&lt;br/&gt;📝 Original message:&amp;gt; &amp;gt; Likewise, I could attach a payment request to an email and send it to you,&lt;br/&gt;&amp;gt; &amp;gt; and now you can pay me whenever you want forever.&lt;br/&gt;&amp;gt; &lt;br/&gt;&amp;gt; That certainly sounds like a plausible use case.  You do still have&lt;br/&gt;&amp;gt; the problem that e-mail is an insecure channel, but it&amp;#39;s no worse than&lt;br/&gt;&amp;gt; exchanging Bitcoin addreses over e-mail as things stand at the&lt;br/&gt;&amp;gt; moment.&lt;br/&gt;&lt;br/&gt;On further reflection, I&amp;#39;m not sure I understand this use case of the&lt;br/&gt;payment protocol.  Since a PaymentRequest currently contains the&lt;br/&gt;Outputs that specify the addresses to send to, reusing a&lt;br/&gt;PaymentRequest like this without using stealth addresses implies&lt;br/&gt;address reuse.&lt;br/&gt;&lt;br/&gt;(Granted there are alternative solutions to stealth addresses, such as&lt;br/&gt;a BIP32-style derivation.)&lt;br/&gt;&lt;br/&gt;roy
    </content>
    <updated>2023-06-07T15:11:51Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsr2r63ug8tncpm3h9s7zfyku5042xcatj6yskukmn3y2gurytukuczypv0zc8qm0rxzczhqjcepcm02xvl3qwgv8jnwc78q4lxhsxp8e54qylw074</id>
    
      <title type="html">📅 Original date posted:2014-01-13 📝 Original message:rOn ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsr2r63ug8tncpm3h9s7zfyku5042xcatj6yskukmn3y2gurytukuczypv0zc8qm0rxzczhqjcepcm02xvl3qwgv8jnwc78q4lxhsxp8e54qylw074" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqswpeqqjuuxnva0urzm0gfdyhej0erp5q9g7lrkete4h0fwyqmp9uqx3k50r&#39;&gt;nevent1q…k50r&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;📅 Original date posted:2014-01-13&lt;br/&gt;📝 Original message:rOn Mon, Jan 13, 2014 at 08:57:33PM &#43;0100, Mike Hearn wrote:&lt;br/&gt;&amp;gt; &amp;gt;&lt;br/&gt;&amp;gt; &amp;gt; On further reflection, I&amp;#39;m not sure I understand this use case of the&lt;br/&gt;&amp;gt; &amp;gt; payment protocol.  Since a PaymentRequest currently contains the&lt;br/&gt;&amp;gt; &amp;gt; Outputs that specify the addresses to send to, reusing a&lt;br/&gt;&amp;gt; &amp;gt; PaymentRequest like this without using stealth addresses implies&lt;br/&gt;&amp;gt; &amp;gt; address reuse.&lt;br/&gt;&amp;gt; &lt;br/&gt;&amp;gt; &lt;br/&gt;&amp;gt; Yes indeed ...... which is why we&amp;#39;re talking about extending the protocol&lt;br/&gt;&amp;gt; (in a future version! the first version isn&amp;#39;t even out yet!).&lt;br/&gt;&lt;br/&gt;Yes, sorry, I miscontrued the thread here and now see that your&lt;br/&gt;message was exactly talking about using stealth addresses within the&lt;br/&gt;payment protocol.&lt;br/&gt;&lt;br/&gt;Sorry for the confusion.&lt;br/&gt;&lt;br/&gt;roy
    </content>
    <updated>2023-06-07T15:11:51Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsva29073q6tj6k82r2q2frmx8v0jm9uf60a2etqjva0mup0r859vqzypv0zc8qm0rxzczhqjcepcm02xvl3qwgv8jnwc78q4lxhsxp8e54qkhns0e</id>
    
      <title type="html">📅 Original date posted:2014-01-15 📝 Original message:On ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsva29073q6tj6k82r2q2frmx8v0jm9uf60a2etqjva0mup0r859vqzypv0zc8qm0rxzczhqjcepcm02xvl3qwgv8jnwc78q4lxhsxp8e54qkhns0e" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsyqt8pdq3n466z8624w4u69qmnt457rc5x924rg3s54yxr4fvkpcs0ql29t&#39;&gt;nevent1q…l29t&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;📅 Original date posted:2014-01-15&lt;br/&gt;📝 Original message:On Wed, Jan 15, 2014 at 11:17:33PM &#43;0000, I wrote:&lt;br/&gt;&amp;gt; How about just calling them &amp;#39;type S addresses&amp;#39;?&lt;br/&gt;&lt;br/&gt;(Assuming they&amp;#39;re encoded in such as way that they actually start with &amp;#39;s&amp;#39;.&lt;br/&gt;Otherwise whatever prefix is actually used, obviously.)
    </content>
    <updated>2023-06-07T15:11:42Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsghnzgce2tjjf6hv8juw08ta7xmss9e02xee4d5cw9qh56d2m9qsgzypv0zc8qm0rxzczhqjcepcm02xvl3qwgv8jnwc78q4lxhsxp8e54qtanyrw</id>
    
      <title type="html">📅 Original date posted:2014-01-15 📝 Original message:On ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsghnzgce2tjjf6hv8juw08ta7xmss9e02xee4d5cw9qh56d2m9qsgzypv0zc8qm0rxzczhqjcepcm02xvl3qwgv8jnwc78q4lxhsxp8e54qtanyrw" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqs80q9kp9g8h68era8r46dj9hf7c4pd6g8dkp7fc9qc77qwe6lu6mqu8uee2&#39;&gt;nevent1q…uee2&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;📅 Original date posted:2014-01-15&lt;br/&gt;📝 Original message:On Wed, Jan 15, 2014 at 03:44:17PM -0500, Jeff Garzik wrote:&lt;br/&gt;&amp;gt; &amp;#34;static address&amp;#34; seems like a reasonable attempt at describing intended&lt;br/&gt;&amp;gt; use/direction.&lt;br/&gt;&lt;br/&gt;...as opposed to an address configured by DHCP?&lt;br/&gt;&lt;br/&gt;More seriously, I don&amp;#39;t think a typical user will understand anything from&lt;br/&gt;the phrase &amp;#34;static address&amp;#34;.  But it is a neutral name, and it is shorter&lt;br/&gt;than &amp;#34;address-of-a-type-for-which-reuse-is-not-deprecated&amp;#34;. :-)&lt;br/&gt;&lt;br/&gt;-roy
    </content>
    <updated>2023-06-07T15:11:42Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsyqt8pdq3n466z8624w4u69qmnt457rc5x924rg3s54yxr4fvkpcszypv0zc8qm0rxzczhqjcepcm02xvl3qwgv8jnwc78q4lxhsxp8e54qd5eg9a</id>
    
      <title type="html">📅 Original date posted:2014-01-15 📝 Original message:How ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsyqt8pdq3n466z8624w4u69qmnt457rc5x924rg3s54yxr4fvkpcszypv0zc8qm0rxzczhqjcepcm02xvl3qwgv8jnwc78q4lxhsxp8e54qd5eg9a" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqswrm43sq40z8qx3f93nc63gnpz9uxsx357pfhk696nh8363sayfdsk3jr80&#39;&gt;nevent1q…jr80&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;📅 Original date posted:2014-01-15&lt;br/&gt;📝 Original message:How about just calling them &amp;#39;type S addresses&amp;#39;?&lt;br/&gt;&lt;br/&gt;Not sure any other name will in reality convey much more meaning than&lt;br/&gt;that.&lt;br/&gt;&lt;br/&gt;On Wed, Jan 15, 2014 at 06:07:28PM -0500, Jeff Garzik wrote:&lt;br/&gt;&amp;gt; &amp;#34;Routing address&amp;#34; is pretty good too.  Unsure whether the synergy and&lt;br/&gt;&amp;gt; familiarity with bank routing numbers improves the situation, or&lt;br/&gt;&amp;gt; not...&lt;br/&gt;&amp;gt; &lt;br/&gt;&amp;gt; &lt;br/&gt;&amp;gt; On Wed, Jan 15, 2014 at 6:04 PM, Roy Badami &amp;lt;roy at gnomon.org.uk&amp;gt; wrote:&lt;br/&gt;&amp;gt; &amp;gt; On Wed, Jan 15, 2014 at 03:44:17PM -0500, Jeff Garzik wrote:&lt;br/&gt;&amp;gt; &amp;gt;&amp;gt; &amp;#34;static address&amp;#34; seems like a reasonable attempt at describing intended&lt;br/&gt;&amp;gt; &amp;gt;&amp;gt; use/direction.&lt;br/&gt;&amp;gt; &amp;gt;&lt;br/&gt;&amp;gt; &amp;gt; ...as opposed to an address configured by DHCP?&lt;br/&gt;&amp;gt; &amp;gt;&lt;br/&gt;&amp;gt; &amp;gt; More seriously, I don&amp;#39;t think a typical user will understand anything from&lt;br/&gt;&amp;gt; &amp;gt; the phrase &amp;#34;static address&amp;#34;.  But it is a neutral name, and it is shorter&lt;br/&gt;&amp;gt; &amp;gt; than &amp;#34;address-of-a-type-for-which-reuse-is-not-deprecated&amp;#34;. :-)&lt;br/&gt;&amp;gt; &amp;gt;&lt;br/&gt;&amp;gt; &amp;gt; -roy&lt;br/&gt;&amp;gt; &lt;br/&gt;&amp;gt; &lt;br/&gt;&amp;gt; &lt;br/&gt;&amp;gt; -- &lt;br/&gt;&amp;gt; Jeff Garzik&lt;br/&gt;&amp;gt; Bitcoin core developer and open source evangelist&lt;br/&gt;&amp;gt; BitPay, Inc.      &lt;a href=&#34;https://bitpay.com/&#34;&gt;https://bitpay.com/&lt;/a&gt;&lt;br/&gt;&amp;gt;
    </content>
    <updated>2023-06-07T15:11:42Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsvama4p3juuppccwrssxseg7f68pcaqhcf42wuq9e4k8jzhjnj5aszypv0zc8qm0rxzczhqjcepcm02xvl3qwgv8jnwc78q4lxhsxp8e54qezpj3x</id>
    
      <title type="html">📅 Original date posted:2014-01-14 📝 Original message:On ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsvama4p3juuppccwrssxseg7f68pcaqhcf42wuq9e4k8jzhjnj5aszypv0zc8qm0rxzczhqjcepcm02xvl3qwgv8jnwc78q4lxhsxp8e54qezpj3x" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsvt0pqy3v00x4zk68f8dylcajlluahthwf9leerqnt85nvaecsvpgelazgy&#39;&gt;nevent1q…azgy&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;📅 Original date posted:2014-01-14&lt;br/&gt;📝 Original message:On Mon, Jan 13, 2014 at 04:58:01PM &#43;0100, Mike Hearn wrote:&lt;br/&gt;&amp;gt; &lt;br/&gt;&amp;gt; Signing a payment request for an individual is easy, anyway, depending on&lt;br/&gt;&amp;gt; the kind of ID you want. If you want to sign with an email address, just go&lt;br/&gt;&amp;gt; here with a browser like Chrome/Safari/IE that uses the system keystore:&lt;br/&gt;&amp;gt; &lt;br/&gt;&amp;gt;    &lt;a href=&#34;http://www.comodo.com/home/email-security/free-email-certificate.php&#34;&gt;http://www.comodo.com/home/email-security/free-email-certificate.php&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;Having now read that page, I&amp;#39;ll just leave you with the first bullet&lt;br/&gt;point from it:&lt;br/&gt;&lt;br/&gt; * Digital signature ensures confidentiality&lt;br/&gt;&lt;br/&gt;(I&amp;#39;m not trying to make any particular point here - I just couldn&amp;#39;t resist)&lt;br/&gt;&lt;br/&gt;&lt;br/&gt;roy
    </content>
    <updated>2023-06-07T15:11:40Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsvt0pqy3v00x4zk68f8dylcajlluahthwf9leerqnt85nvaecsvpgzypv0zc8qm0rxzczhqjcepcm02xvl3qwgv8jnwc78q4lxhsxp8e54qcp9vc0</id>
    
      <title type="html">📅 Original date posted:2014-01-13 📝 Original message:On ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsvt0pqy3v00x4zk68f8dylcajlluahthwf9leerqnt85nvaecsvpgzypv0zc8qm0rxzczhqjcepcm02xvl3qwgv8jnwc78q4lxhsxp8e54qcp9vc0" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqstvkymceqvcnqxky6rgp4r0evywzpjt3mkyusxz75rhtnpp0pqcrgpn6mxp&#39;&gt;nevent1q…6mxp&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;📅 Original date posted:2014-01-13&lt;br/&gt;📝 Original message:On Mon, Jan 13, 2014 at 04:58:01PM &#43;0100, Mike Hearn wrote:&lt;br/&gt;&amp;gt; Signing a payment request for an individual is easy, anyway, depending on&lt;br/&gt;&amp;gt; the kind of ID you want. If you want to sign with an email address, just go&lt;br/&gt;&amp;gt; here with a browser like Chrome/Safari/IE that uses the system keystore:&lt;br/&gt;&amp;gt; &lt;br/&gt;&amp;gt;    &lt;a href=&#34;http://www.comodo.com/home/email-security/free-email-certificate.php&#34;&gt;http://www.comodo.com/home/email-security/free-email-certificate.php&lt;/a&gt;&lt;br/&gt;&amp;gt; &lt;br/&gt;&lt;br/&gt;Ok, cool, I wasn&amp;#39;t aware of such services, and I can certainly see&lt;br/&gt;they could be useful.  But it&amp;#39;s not that great for the business card&lt;br/&gt;scenario.&lt;br/&gt;&lt;br/&gt;As far as I can see, using it in that scenario would have to rely on&lt;br/&gt;the payer scanning the QR code on the business card, and then check&lt;br/&gt;that the email address displayed by their wallet matched the email&lt;br/&gt;address printed on the business card.&lt;br/&gt;&lt;br/&gt;roy
    </content>
    <updated>2023-06-07T15:11:40Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsyegsqy7fj949va3n5huhca4nj5cvlxrjldqffrd8kkphzu03x45gzypv0zc8qm0rxzczhqjcepcm02xvl3qwgv8jnwc78q4lxhsxp8e54qn4rvwg</id>
    
      <title type="html">📅 Original date posted:2014-01-13 📝 Original message:&amp;gt; I ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsyegsqy7fj949va3n5huhca4nj5cvlxrjldqffrd8kkphzu03x45gzypv0zc8qm0rxzczhqjcepcm02xvl3qwgv8jnwc78q4lxhsxp8e54qn4rvwg" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsrlr2p8ey0nvq3gdatanrgenhe5yq66d4uk5ge4wwhj4us588gm0qkaj3d6&#39;&gt;nevent1q…j3d6&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;📅 Original date posted:2014-01-13&lt;br/&gt;📝 Original message:&amp;gt; I was thinking that people could upload a payment protocol file somewhere&lt;br/&gt;&amp;gt; once (like to their personal web page, or shared via dropbox or google&lt;br/&gt;&amp;gt; drive or some custom new pastebin style service), and then just encode a&lt;br/&gt;&amp;gt; regular bitcoin URI into the qrcode on the billboard.&lt;br/&gt;&lt;br/&gt;That does require trusting the third party not to later tamper with&lt;br/&gt;the payment request, though.  (I&amp;#39;m assuming that a signed payment&lt;br/&gt;request is not always going to be all that useful in the case of&lt;br/&gt;private individuals, even assuming the payee is willing to sign up for&lt;br/&gt;one.)&lt;br/&gt;&lt;br/&gt;&amp;gt; Likewise, I could attach a payment request to an email and send it to you,&lt;br/&gt;&amp;gt; and now you can pay me whenever you want forever.&lt;br/&gt;&lt;br/&gt;That certainly sounds like a plausible use case.  You do still have&lt;br/&gt;the problem that e-mail is an insecure channel, but it&amp;#39;s no worse than&lt;br/&gt;exchanging Bitcoin addreses over e-mail as things stand at the&lt;br/&gt;moment.&lt;br/&gt;&lt;br/&gt;roy
    </content>
    <updated>2023-06-07T15:11:39Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsr9qhpj7a2j52460gxy7swau2d0qq9lcrajzhm7tk0y0ppc37kdfszypv0zc8qm0rxzczhqjcepcm02xvl3qwgv8jnwc78q4lxhsxp8e54qqpfmlv</id>
    
      <title type="html">📅 Original date posted:2013-12-08 📝 Original message:&amp;gt; ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsr9qhpj7a2j52460gxy7swau2d0qq9lcrajzhm7tk0y0ppc37kdfszypv0zc8qm0rxzczhqjcepcm02xvl3qwgv8jnwc78q4lxhsxp8e54qqpfmlv" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsgklu4kul2wqr59hr8utnew85l9drjvlzvt2w8c8dwvauc3z7s7vcy3x7vn&#39;&gt;nevent1q…x7vn&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;📅 Original date posted:2013-12-08&lt;br/&gt;📝 Original message:&amp;gt; &amp;gt; 5) Who controls DNS for it?&lt;br/&gt;&amp;gt; &lt;br/&gt;&amp;gt; I&amp;#39;m not sure we&amp;#39;ll get any change on this level. I have no idea if the&lt;br/&gt;&amp;gt; domain is in good hands, except for the fact that nothing bad happened&lt;br/&gt;&amp;gt; thus far. If anything, moving it to core developers (as intended when&lt;br/&gt;&amp;gt; the domain was registered) would make more sense IMO. But again, is it&lt;br/&gt;&amp;gt; possible, I don&amp;#39;t know.&lt;br/&gt;&lt;br/&gt;That&amp;#39;s an interesting question.  The bitcoin.org domain is hiding&lt;br/&gt;behind a WhoisGuard anonymous registration.  Why are we not allowed to&lt;br/&gt;know who this domain belongs to?  Why are we being asked to trust some&lt;br/&gt;unidentified party?&lt;br/&gt;&lt;br/&gt;roy
    </content>
    <updated>2023-06-07T15:10:28Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqs8ae0e7x849dc5yluzutar5m6t8nzagwy3kn3z7n5wfhrywgfghyszypv0zc8qm0rxzczhqjcepcm02xvl3qwgv8jnwc78q4lxhsxp8e54qez4zqg</id>
    
      <title type="html">📅 Original date posted:2013-12-09 📝 Original message:&amp;gt; ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqs8ae0e7x849dc5yluzutar5m6t8nzagwy3kn3z7n5wfhrywgfghyszypv0zc8qm0rxzczhqjcepcm02xvl3qwgv8jnwc78q4lxhsxp8e54qez4zqg" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqspvqsp5x7fs42yl086qm2jw6a0g8tuyex4z9uewhpxcyc5t8ydgmqc4zje9&#39;&gt;nevent1q…zje9&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;📅 Original date posted:2013-12-09&lt;br/&gt;📝 Original message:&amp;gt; The bitcoin.org domain is controlled by me, Sirius, and an anonymous&lt;br/&gt;&amp;gt; person. Control will not be lost if Sirius becomes unavailable.&lt;br/&gt;&lt;br/&gt;I know this will be a controversial viewpoint in some quarters, but&lt;br/&gt;I&amp;#39;m not a fan of anonymity, or of pseudonyms.  As far as I know&lt;br/&gt;(please correct me if I&amp;#39;m wrong) all the core devs go by their real&lt;br/&gt;names with the exception of Satoshi (and I would hope he no longer has&lt;br/&gt;commit access? - only because I would hope that no-one has&lt;br/&gt;pseudonymous commit access these days).  I don&amp;#39;t see why this should&lt;br/&gt;be different for the domain, the DNS and the rest of the&lt;br/&gt;infrastructure...&lt;br/&gt;&lt;br/&gt;Although that&amp;#39;s separate from the question of who the registrant of&lt;br/&gt;the domain should be (the registrant being the closest thing a domain&lt;br/&gt;has to a recorded legal owner).  Who currently purports to be the&lt;br/&gt;current legal owner of the domain?&lt;br/&gt;&lt;br/&gt;IMHO the registrant should obviously be real and not WhoisGuard -&lt;br/&gt;anonymous stuff like this always looks shady.  And surely the Bitcoin&lt;br/&gt;Foundation is the obvious candidate to own the domain (just like&lt;br/&gt;kernel.org is owned by the Linux Foundation).  But this may all be&lt;br/&gt;moot unless the current legal owners are willing to assign the&lt;br/&gt;domain...&lt;br/&gt;&lt;br/&gt;roy
    </content>
    <updated>2023-06-07T15:10:27Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsyg8xc8sz90ctej5j2u85agmu2k5mxfw6wnxu2lyzmmr8edw6f2uszypv0zc8qm0rxzczhqjcepcm02xvl3qwgv8jnwc78q4lxhsxp8e54q6q782v</id>
    
      <title type="html">📅 Original date posted:2013-12-09 📝 Original message:On ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsyg8xc8sz90ctej5j2u85agmu2k5mxfw6wnxu2lyzmmr8edw6f2uszypv0zc8qm0rxzczhqjcepcm02xvl3qwgv8jnwc78q4lxhsxp8e54q6q782v" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqswzttq9hxhxqv2vhkq4fchgg4033uf6zqjpjdnexa5aft7zerr7rqpdyutx&#39;&gt;nevent1q…yutx&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;📅 Original date posted:2013-12-09&lt;br/&gt;📝 Original message:On Mon, Dec 09, 2013 at 01:39:51PM &#43;0000, Drak wrote:&lt;br/&gt;&amp;gt; Someone needs to update the bitcoin.org website, it still points downloads&lt;br/&gt;&amp;gt; to 0.8.5&lt;br/&gt;&lt;br/&gt;Perhaps because 0.8.6 hasn&amp;#39;t been released yet?  Or did I miss the&lt;br/&gt;announcement?  I think it makes sense that release candidates are not&lt;br/&gt;promoted on bitcoin.org.&lt;br/&gt;&lt;br/&gt;&amp;gt; ------------------------------------------------------------------------------&lt;br/&gt;&amp;gt; Sponsored by Intel(R) XDK &lt;br/&gt;&amp;gt; Develop, test and display web and hybrid apps with a single code base.&lt;br/&gt;&amp;gt; Download it for free now!&lt;br/&gt;&amp;gt; &lt;a href=&#34;http://pubads.g.doubleclick.net/gampad/clk?id=111408631&amp;amp;iu=/4140/ostg.clktrk&#34;&gt;http://pubads.g.doubleclick.net/gampad/clk?id=111408631&amp;amp;iu=/4140/ostg.clktrk&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;&amp;gt; _______________________________________________&lt;br/&gt;&amp;gt; Bitcoin-development mailing list&lt;br/&gt;&amp;gt; Bitcoin-development at lists.sourceforge.net&lt;br/&gt;&amp;gt; &lt;a href=&#34;https://lists.sourceforge.net/lists/listinfo/bitcoin-development&#34;&gt;https://lists.sourceforge.net/lists/listinfo/bitcoin-development&lt;/a&gt;
    </content>
    <updated>2023-06-07T15:10:20Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqs9j53gttayucqpgrmfu3afgtd7parwrpt2vstcg04av5npd5yu6eszypv0zc8qm0rxzczhqjcepcm02xvl3qwgv8jnwc78q4lxhsxp8e54qqqfrsa</id>
    
      <title type="html">📅 Original date posted:2013-08-07 📝 Original message:On ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqs9j53gttayucqpgrmfu3afgtd7parwrpt2vstcg04av5npd5yu6eszypv0zc8qm0rxzczhqjcepcm02xvl3qwgv8jnwc78q4lxhsxp8e54qqqfrsa" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqswltmty3720gzd840q5gvsmrjx2y39hejwrkmck2ew076uqtn8t0sq22ll4&#39;&gt;nevent1q…2ll4&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;📅 Original date posted:2013-08-07&lt;br/&gt;📝 Original message:On Thu, Aug 08, 2013 at 07:10:05AM &#43;1000, Gavin Andresen wrote:&lt;br/&gt;&amp;gt; RE: should the customer&amp;#39;s machine not broadcast the transaction:&lt;br/&gt;&lt;br/&gt;If we&amp;#39;re going to allow payments to fail without being broadcast (but&lt;br/&gt;where the wallet can&amp;#39;t in general prove that the receiver hasn&amp;#39;t seen&lt;br/&gt;the transaction) then I would argue that it becomes highly desirable&lt;br/&gt;that the wallet invalidates the transaction at the earliest&lt;br/&gt;opportunity by spending the outputs in a pay-to-self transaction.&lt;br/&gt;&lt;br/&gt;Otherwise malicious receivers, or temporary failures, could result in&lt;br/&gt;the user being told that the transfer didn&amp;#39;t happen, but then the&lt;br/&gt;coins actually leaving the wallet anyway a short time later.&lt;br/&gt;&lt;br/&gt;roy
    </content>
    <updated>2023-06-07T15:05:37Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsf2gt7dfm8eslvgynzjyks7jz03h9jn3ch4jns074jr69azhlxewczypv0zc8qm0rxzczhqjcepcm02xvl3qwgv8jnwc78q4lxhsxp8e54q9n6zg0</id>
    
      <title type="html">📅 Original date posted:2013-08-07 📝 Original message:On ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsf2gt7dfm8eslvgynzjyks7jz03h9jn3ch4jns074jr69azhlxewczypv0zc8qm0rxzczhqjcepcm02xvl3qwgv8jnwc78q4lxhsxp8e54q9n6zg0" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsvtet098mn4cphsq75cpmpdt3tzvgszja0vt657yyh8s93k6za76qpfurq9&#39;&gt;nevent1q…urq9&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;📅 Original date posted:2013-08-07&lt;br/&gt;📝 Original message:On Wed, Jul 31, 2013 at 05:30:46PM -0600, E willbefull wrote:&lt;br/&gt;&amp;gt; I think it&amp;#39;s important to expect PaymentRequest-only bitcoin URIs in the&lt;br/&gt;&amp;gt; future. Some types of payments (exotic transactions) may not make sense to&lt;br/&gt;&amp;gt; have a single fallback address. Or, a page with a bitcoin URI link may be&lt;br/&gt;&amp;gt; relying on a separate service provider to assemble the transaction.&lt;br/&gt;&lt;br/&gt;Also:&lt;br/&gt;&lt;br/&gt;* There may be a desire to minimize the URL length when used in a QR code&lt;br/&gt;&lt;br/&gt;* Some applications might specifically require some of the features of&lt;br/&gt;the payment protocol - e.g. it may be a requirement that a print-media&lt;br/&gt;QR code cannot be used after a cut-off date, or a vendor may have a&lt;br/&gt;specific requirement not to accept payments without a refund address&lt;br/&gt;&lt;br/&gt;There are pros and cons, but it&amp;#39;s not clear to me that the benefits of&lt;br/&gt;enforced backward compatibility outweigh the benefits of allowing&lt;br/&gt;application designers to innovate as they see fit.&lt;br/&gt;&lt;br/&gt;roy
    </content>
    <updated>2023-06-07T15:05:36Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqspua0uaqlklpj0vc3av7r9qzxe6tfn8hwrudvhfkmtpm7zd0m3w7qzypv0zc8qm0rxzczhqjcepcm02xvl3qwgv8jnwc78q4lxhsxp8e54qvpqm8y</id>
    
      <title type="html">📅 Original date posted:2013-06-04 📝 Original message:&amp;gt; ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqspua0uaqlklpj0vc3av7r9qzxe6tfn8hwrudvhfkmtpm7zd0m3w7qzypv0zc8qm0rxzczhqjcepcm02xvl3qwgv8jnwc78q4lxhsxp8e54qvpqm8y" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsfxuuy5nm73yt78tw6ttfz7wwv6drmv7w9wv99shsjwtkpen6t4vqdggn7c&#39;&gt;nevent1q…gn7c&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;📅 Original date posted:2013-06-04&lt;br/&gt;📝 Original message:&amp;gt; Sure they are paying themselves, but given bitcoin network&lt;br/&gt;&amp;gt; difficulty is uso high, simply obtaining payments-go-myself-as-miner&lt;br/&gt;&amp;gt; transactions is itself difficult.&lt;br/&gt;&lt;br/&gt;Not for pool operators it isn&amp;#39;t.  Nor for people buying hashing power&lt;br/&gt;from a GPUMAX-type service, if such services still exist (or should&lt;br/&gt;they exist again in future).
    </content>
    <updated>2023-06-07T15:02:39Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqs82c3w99xcsug6x4m4pvfzwswqluufvchnt3a2c786zqjemfwvaaszypv0zc8qm0rxzczhqjcepcm02xvl3qwgv8jnwc78q4lxhsxp8e54qklsw78</id>
    
      <title type="html">📅 Original date posted:2013-04-01 📝 Original message:And ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqs82c3w99xcsug6x4m4pvfzwswqluufvchnt3a2c786zqjemfwvaaszypv0zc8qm0rxzczhqjcepcm02xvl3qwgv8jnwc78q4lxhsxp8e54qklsw78" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsz3erzulwmk9vhke5w858m0vvlt4z78pdvy6rh3gen34rhdm9l30slpcfc6&#39;&gt;nevent1q…cfc6&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;📅 Original date posted:2013-04-01&lt;br/&gt;📝 Original message:And the moment I hit send I realised it&amp;#39;s not necessarily true.&lt;br/&gt;Conceivably, a collision attack might help you craft two commits (one&lt;br/&gt;good, one bad) with the same hash.&lt;br/&gt;&lt;br/&gt;But I still maintain what I just posted is true: if someone gets&lt;br/&gt;malicious code into the repo, it&amp;#39;s going to be by social engineering,&lt;br/&gt;not by breaking the cyrpto.&lt;br/&gt;&lt;br/&gt;roy&lt;br/&gt;&lt;br/&gt;&lt;br/&gt;On Mon, Apr 01, 2013 at 11:51:07PM &#43;0100, Roy Badami wrote:&lt;br/&gt;&amp;gt; The attack Schneier is talking about is a collision attack (i.e. it&lt;br/&gt;&amp;gt; creates two messages with the same hash, but you don&amp;#39;t get to choose&lt;br/&gt;&amp;gt; either of the messages).  It&amp;#39;s not a second preimage attack, which is&lt;br/&gt;&amp;gt; what you would need to be able to create a message that hashes to the&lt;br/&gt;&amp;gt; same value of an existing message.&lt;br/&gt;&amp;gt; &lt;br/&gt;&amp;gt; (And it neither have anything to do with the birthday paradox, BTW -&lt;br/&gt;&amp;gt; which relates to the chance of eventually finding two messages that&lt;br/&gt;&amp;gt; hash to the same value by pure change)&lt;br/&gt;&amp;gt; &lt;br/&gt;&amp;gt; If someone gets malicious code into the repo, it&amp;#39;s going to be by&lt;br/&gt;&amp;gt; social engineering, not by breaking the cyrpto.&lt;br/&gt;&amp;gt; &lt;br/&gt;&amp;gt; roy&lt;br/&gt;&amp;gt; &lt;br/&gt;&amp;gt; On Tue, Apr 02, 2013 at 12:27:51AM &#43;0200, Melvin Carvalho wrote:&lt;br/&gt;&amp;gt; &amp;gt; On 2 April 2013 00:10, Will &amp;lt;will at phase.net&amp;gt; wrote:&lt;br/&gt;&amp;gt; &amp;gt; &lt;br/&gt;&amp;gt; &amp;gt; &amp;gt; The threat of a SHA1 collision attack to insert a malicious pull request&lt;br/&gt;&amp;gt; &amp;gt; &amp;gt; are tiny compared with the other threats - e.g. github being compromised,&lt;br/&gt;&amp;gt; &amp;gt; &amp;gt; one of the core developers&amp;#39; passwords being compromised, one of the core&lt;br/&gt;&amp;gt; &amp;gt; &amp;gt; developers going rogue, sourceforge (distribution site) being compromised&lt;br/&gt;&amp;gt; &amp;gt; &amp;gt; etc etc... believe me there&amp;#39;s a lot more to worry about than a SHA1&lt;br/&gt;&amp;gt; &amp;gt; &amp;gt; attack...&lt;br/&gt;&amp;gt; &amp;gt; &amp;gt;&lt;br/&gt;&amp;gt; &amp;gt; &amp;gt; Not meaning to scare, just to put things in perspective - this is why we&lt;br/&gt;&amp;gt; &amp;gt; &amp;gt; all need to peer review each others commits and keep an eye out for&lt;br/&gt;&amp;gt; &amp;gt; &amp;gt; suspicious commits, leverage the benefits of this project being open source&lt;br/&gt;&amp;gt; &amp;gt; &amp;gt; and easily peer reviewed.&lt;br/&gt;&amp;gt; &amp;gt; &amp;gt;&lt;br/&gt;&amp;gt; &amp;gt; &lt;br/&gt;&amp;gt; &amp;gt; Very good points, and I think you&amp;#39;re absolutely right.&lt;br/&gt;&amp;gt; &amp;gt; &lt;br/&gt;&amp;gt; &amp;gt; But just running the numbers, to get the picture, based of scheiner&amp;#39;s&lt;br/&gt;&amp;gt; &amp;gt; statistics:&lt;br/&gt;&amp;gt; &amp;gt; &lt;br/&gt;&amp;gt; &amp;gt; &lt;a href=&#34;http://www.schneier.com/blog/archives/2012/10/when_will_we_se.html&#34;&gt;http://www.schneier.com/blog/archives/2012/10/when_will_we_se.html&lt;/a&gt;&lt;br/&gt;&amp;gt; &amp;gt; &lt;br/&gt;&amp;gt; &amp;gt; We&amp;#39;re talking about a million terrahashes = 2^60 right?&lt;br/&gt;&amp;gt; &amp;gt; &lt;br/&gt;&amp;gt; &amp;gt; With the block chain, you only have a 10 minute window, but with source&lt;br/&gt;&amp;gt; &amp;gt; code you have a longer time to prepare.&lt;br/&gt;&amp;gt; &amp;gt; &lt;br/&gt;&amp;gt; &amp;gt; Couldnt this be done with an ASIC in about a week?&lt;br/&gt;&amp;gt; &amp;gt; &lt;br/&gt;&amp;gt; &amp;gt; &lt;br/&gt;&amp;gt; &amp;gt; &lt;br/&gt;&amp;gt; &amp;gt; &amp;gt;&lt;br/&gt;&amp;gt; &amp;gt; &amp;gt; Will&lt;br/&gt;&amp;gt; &amp;gt; &amp;gt;&lt;br/&gt;&amp;gt; &amp;gt; &amp;gt;&lt;br/&gt;&amp;gt; &amp;gt; &amp;gt; On 1 April 2013 23:52, Melvin Carvalho &amp;lt;melvincarvalho at gmail.com&amp;gt; wrote:&lt;br/&gt;&amp;gt; &amp;gt; &amp;gt;&lt;br/&gt;&amp;gt; &amp;gt; &amp;gt;&amp;gt;&lt;br/&gt;&amp;gt; &amp;gt; &amp;gt;&amp;gt;&lt;br/&gt;&amp;gt; &amp;gt; &amp;gt;&amp;gt;&lt;br/&gt;&amp;gt; &amp;gt; &amp;gt;&amp;gt; On 1 April 2013 20:28, Petr Praus &amp;lt;petr at praus.net&amp;gt; wrote:&lt;br/&gt;&amp;gt; &amp;gt; &amp;gt;&amp;gt;&lt;br/&gt;&amp;gt; &amp;gt; &amp;gt;&amp;gt;&amp;gt; An attacker would have to find a collision between two specific pieces&lt;br/&gt;&amp;gt; &amp;gt; &amp;gt;&amp;gt;&amp;gt; of code - his malicious code and a useful innoculous code that would be&lt;br/&gt;&amp;gt; &amp;gt; &amp;gt;&amp;gt;&amp;gt; accepted as pull request. This is the second, much harder case in the&lt;br/&gt;&amp;gt; &amp;gt; &amp;gt;&amp;gt;&amp;gt; birthday problem. When people talk about SHA-1 being broken they actually&lt;br/&gt;&amp;gt; &amp;gt; &amp;gt;&amp;gt;&amp;gt; mean the first case in the birthday problem - find any two arbitrary values&lt;br/&gt;&amp;gt; &amp;gt; &amp;gt;&amp;gt;&amp;gt; that hash to the same value. So, no I don&amp;#39;t think it&amp;#39;s a feasible attack&lt;br/&gt;&amp;gt; &amp;gt; &amp;gt;&amp;gt;&amp;gt; vector any time soon.&lt;br/&gt;&amp;gt; &amp;gt; &amp;gt;&amp;gt;&amp;gt;&lt;br/&gt;&amp;gt; &amp;gt; &amp;gt;&amp;gt;&amp;gt; Besides, with that kind of hashing power, it might be more feasible to&lt;br/&gt;&amp;gt; &amp;gt; &amp;gt;&amp;gt;&amp;gt; cause problems in the chain by e.g. constantly splitting it.&lt;br/&gt;&amp;gt; &amp;gt; &amp;gt;&amp;gt;&amp;gt;&lt;br/&gt;&amp;gt; &amp;gt; &amp;gt;&amp;gt;&lt;br/&gt;&amp;gt; &amp;gt; &amp;gt;&amp;gt; OK, maybe im being *way* too paranoid here ... but what if someone had&lt;br/&gt;&amp;gt; &amp;gt; &amp;gt;&amp;gt; access to github, could they replace one file with one they had prepared at&lt;br/&gt;&amp;gt; &amp;gt; &amp;gt;&amp;gt; some point?&lt;br/&gt;&amp;gt; &amp;gt; &amp;gt;&amp;gt;&lt;br/&gt;&amp;gt; &amp;gt; &amp;gt;&amp;gt;&lt;br/&gt;&amp;gt; &amp;gt; &amp;gt;&amp;gt;&amp;gt;&lt;br/&gt;&amp;gt; &amp;gt; &amp;gt;&amp;gt;&amp;gt;&lt;br/&gt;&amp;gt; &amp;gt; &amp;gt;&amp;gt;&amp;gt; On 1 April 2013 03:26, Melvin Carvalho &amp;lt;melvincarvalho at gmail.com&amp;gt; wrote:&lt;br/&gt;&amp;gt; &amp;gt; &amp;gt;&amp;gt;&amp;gt;&lt;br/&gt;&amp;gt; &amp;gt; &amp;gt;&amp;gt;&amp;gt;&amp;gt;  I was just looking at:&lt;br/&gt;&amp;gt; &amp;gt; &amp;gt;&amp;gt;&amp;gt;&amp;gt;&lt;br/&gt;&amp;gt; &amp;gt; &amp;gt;&amp;gt;&amp;gt;&amp;gt; &lt;a href=&#34;https://bitcointalk.org/index.php?topic=4571.0&#34;&gt;https://bitcointalk.org/index.php?topic=4571.0&lt;/a&gt;&lt;br/&gt;&amp;gt; &amp;gt; &amp;gt;&amp;gt;&amp;gt;&amp;gt;&lt;br/&gt;&amp;gt; &amp;gt; &amp;gt;&amp;gt;&amp;gt;&amp;gt; I&amp;#39;m just curious if there is a possible attack vector here based on the&lt;br/&gt;&amp;gt; &amp;gt; &amp;gt;&amp;gt;&amp;gt;&amp;gt; fact that git uses the relatively week SHA1&lt;br/&gt;&amp;gt; &amp;gt; &amp;gt;&amp;gt;&amp;gt;&amp;gt;&lt;br/&gt;&amp;gt; &amp;gt; &amp;gt;&amp;gt;&amp;gt;&amp;gt; Could a seemingly innocuous pull request generate another file with a&lt;br/&gt;&amp;gt; &amp;gt; &amp;gt;&amp;gt;&amp;gt;&amp;gt; backdoor/nonce combination that slips under the radar?&lt;br/&gt;&amp;gt; &amp;gt; &amp;gt;&amp;gt;&amp;gt;&amp;gt;&lt;br/&gt;&amp;gt; &amp;gt; &amp;gt;&amp;gt;&amp;gt;&amp;gt; Apologies if this has come up before ...&lt;br/&gt;&amp;gt; &amp;gt; &amp;gt;&amp;gt;&amp;gt;&amp;gt;&lt;br/&gt;&amp;gt; &amp;gt; &amp;gt;&amp;gt;&amp;gt;&amp;gt;&lt;br/&gt;&amp;gt; &amp;gt; &amp;gt;&amp;gt;&amp;gt;&amp;gt; ------------------------------------------------------------------------------&lt;br/&gt;&amp;gt; &amp;gt; &amp;gt;&amp;gt;&amp;gt;&amp;gt; Own the Future-Intel&amp;amp;reg; Level Up Game Demo Contest 2013&lt;br/&gt;&amp;gt; &amp;gt; &amp;gt;&amp;gt;&amp;gt;&amp;gt; Rise to greatness in Intel&amp;#39;s independent game demo contest.&lt;br/&gt;&amp;gt; &amp;gt; &amp;gt;&amp;gt;&amp;gt;&amp;gt; Compete for recognition, cash, and the chance to get your game&lt;br/&gt;&amp;gt; &amp;gt; &amp;gt;&amp;gt;&amp;gt;&amp;gt; on Steam. $5K grand prize plus 10 genre and skill prizes.&lt;br/&gt;&amp;gt; &amp;gt; &amp;gt;&amp;gt;&amp;gt;&amp;gt; Submit your demo by 6/6/13. &lt;a href=&#34;http://p.sf.net/sfu/intel_levelupd2d&#34;&gt;http://p.sf.net/sfu/intel_levelupd2d&lt;/a&gt;&lt;br/&gt;&amp;gt; &amp;gt; &amp;gt;&amp;gt;&amp;gt;&amp;gt; _______________________________________________&lt;br/&gt;&amp;gt; &amp;gt; &amp;gt;&amp;gt;&amp;gt;&amp;gt; Bitcoin-development mailing list&lt;br/&gt;&amp;gt; &amp;gt; &amp;gt;&amp;gt;&amp;gt;&amp;gt; Bitcoin-development at lists.sourceforge.net&lt;br/&gt;&amp;gt; &amp;gt; &amp;gt;&amp;gt;&amp;gt;&amp;gt; &lt;a href=&#34;https://lists.sourceforge.net/lists/listinfo/bitcoin-development&#34;&gt;https://lists.sourceforge.net/lists/listinfo/bitcoin-development&lt;/a&gt;&lt;br/&gt;&amp;gt; &amp;gt; &amp;gt;&amp;gt;&amp;gt;&amp;gt;&lt;br/&gt;&amp;gt; &amp;gt; &amp;gt;&amp;gt;&amp;gt;&amp;gt;&lt;br/&gt;&amp;gt; &amp;gt; &amp;gt;&amp;gt;&amp;gt;&lt;br/&gt;&amp;gt; &amp;gt; &amp;gt;&amp;gt;&lt;br/&gt;&amp;gt; &amp;gt; &amp;gt;&amp;gt;&lt;br/&gt;&amp;gt; &amp;gt; &amp;gt;&amp;gt; ------------------------------------------------------------------------------&lt;br/&gt;&amp;gt; &amp;gt; &amp;gt;&amp;gt; Own the Future-Intel&amp;amp;reg; Level Up Game Demo Contest 2013&lt;br/&gt;&amp;gt; &amp;gt; &amp;gt;&amp;gt; Rise to greatness in Intel&amp;#39;s independent game demo contest.&lt;br/&gt;&amp;gt; &amp;gt; &amp;gt;&amp;gt; Compete for recognition, cash, and the chance to get your game&lt;br/&gt;&amp;gt; &amp;gt; &amp;gt;&amp;gt; on Steam. $5K grand prize plus 10 genre and skill prizes.&lt;br/&gt;&amp;gt; &amp;gt; &amp;gt;&amp;gt; Submit your demo by 6/6/13. &lt;a href=&#34;http://p.sf.net/sfu/intel_levelupd2d&#34;&gt;http://p.sf.net/sfu/intel_levelupd2d&lt;/a&gt;&lt;br/&gt;&amp;gt; &amp;gt; &amp;gt;&amp;gt; _______________________________________________&lt;br/&gt;&amp;gt; &amp;gt; &amp;gt;&amp;gt; Bitcoin-development mailing list&lt;br/&gt;&amp;gt; &amp;gt; &amp;gt;&amp;gt; Bitcoin-development at lists.sourceforge.net&lt;br/&gt;&amp;gt; &amp;gt; &amp;gt;&amp;gt; &lt;a href=&#34;https://lists.sourceforge.net/lists/listinfo/bitcoin-development&#34;&gt;https://lists.sourceforge.net/lists/listinfo/bitcoin-development&lt;/a&gt;&lt;br/&gt;&amp;gt; &amp;gt; &amp;gt;&amp;gt;&lt;br/&gt;&amp;gt; &amp;gt; &amp;gt;&amp;gt;&lt;br/&gt;&amp;gt; &amp;gt; &amp;gt;&lt;br/&gt;&amp;gt; &lt;br/&gt;&amp;gt; &amp;gt; ------------------------------------------------------------------------------&lt;br/&gt;&amp;gt; &amp;gt; Own the Future-Intel&amp;amp;reg; Level Up Game Demo Contest 2013&lt;br/&gt;&amp;gt; &amp;gt; Rise to greatness in Intel&amp;#39;s independent game demo contest.&lt;br/&gt;&amp;gt; &amp;gt; Compete for recognition, cash, and the chance to get your game &lt;br/&gt;&amp;gt; &amp;gt; on Steam. $5K grand prize plus 10 genre and skill prizes. &lt;br/&gt;&amp;gt; &amp;gt; Submit your demo by 6/6/13. &lt;a href=&#34;http://p.sf.net/sfu/intel_levelupd2d&#34;&gt;http://p.sf.net/sfu/intel_levelupd2d&lt;/a&gt;&lt;br/&gt;&amp;gt; &lt;br/&gt;&amp;gt; &amp;gt; _______________________________________________&lt;br/&gt;&amp;gt; &amp;gt; Bitcoin-development mailing list&lt;br/&gt;&amp;gt; &amp;gt; Bitcoin-development at lists.sourceforge.net&lt;br/&gt;&amp;gt; &amp;gt; &lt;a href=&#34;https://lists.sourceforge.net/lists/listinfo/bitcoin-development&#34;&gt;https://lists.sourceforge.net/lists/listinfo/bitcoin-development&lt;/a&gt;&lt;br/&gt;&amp;gt; &lt;br/&gt;&amp;gt; &lt;br/&gt;&amp;gt; ------------------------------------------------------------------------------&lt;br/&gt;&amp;gt; Own the Future-Intel&amp;amp;reg; Level Up Game Demo Contest 2013&lt;br/&gt;&amp;gt; Rise to greatness in Intel&amp;#39;s independent game demo contest.&lt;br/&gt;&amp;gt; Compete for recognition, cash, and the chance to get your game &lt;br/&gt;&amp;gt; on Steam. $5K grand prize plus 10 genre and skill prizes. &lt;br/&gt;&amp;gt; Submit your demo by 6/6/13. &lt;a href=&#34;http://p.sf.net/sfu/intel_levelupd2d&#34;&gt;http://p.sf.net/sfu/intel_levelupd2d&lt;/a&gt;&lt;br/&gt;&amp;gt; _______________________________________________&lt;br/&gt;&amp;gt; Bitcoin-development mailing list&lt;br/&gt;&amp;gt; Bitcoin-development at lists.sourceforge.net&lt;br/&gt;&amp;gt; &lt;a href=&#34;https://lists.sourceforge.net/lists/listinfo/bitcoin-development&#34;&gt;https://lists.sourceforge.net/lists/listinfo/bitcoin-development&lt;/a&gt;&lt;br/&gt;&amp;gt;
    </content>
    <updated>2023-06-07T11:42:50Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsz3erzulwmk9vhke5w858m0vvlt4z78pdvy6rh3gen34rhdm9l30szypv0zc8qm0rxzczhqjcepcm02xvl3qwgv8jnwc78q4lxhsxp8e54q2p8jj9</id>
    
      <title type="html">📅 Original date posted:2013-04-01 📝 Original message:The ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsz3erzulwmk9vhke5w858m0vvlt4z78pdvy6rh3gen34rhdm9l30szypv0zc8qm0rxzczhqjcepcm02xvl3qwgv8jnwc78q4lxhsxp8e54q2p8jj9" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqswaft9heam97pzdw63l58779cccw0pgrut2r59c39q3awzt0t8mvgada52c&#39;&gt;nevent1q…a52c&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;📅 Original date posted:2013-04-01&lt;br/&gt;📝 Original message:The attack Schneier is talking about is a collision attack (i.e. it&lt;br/&gt;creates two messages with the same hash, but you don&amp;#39;t get to choose&lt;br/&gt;either of the messages).  It&amp;#39;s not a second preimage attack, which is&lt;br/&gt;what you would need to be able to create a message that hashes to the&lt;br/&gt;same value of an existing message.&lt;br/&gt;&lt;br/&gt;(And it neither have anything to do with the birthday paradox, BTW -&lt;br/&gt;which relates to the chance of eventually finding two messages that&lt;br/&gt;hash to the same value by pure change)&lt;br/&gt;&lt;br/&gt;If someone gets malicious code into the repo, it&amp;#39;s going to be by&lt;br/&gt;social engineering, not by breaking the cyrpto.&lt;br/&gt;&lt;br/&gt;roy&lt;br/&gt;&lt;br/&gt;On Tue, Apr 02, 2013 at 12:27:51AM &#43;0200, Melvin Carvalho wrote:&lt;br/&gt;&amp;gt; On 2 April 2013 00:10, Will &amp;lt;will at phase.net&amp;gt; wrote:&lt;br/&gt;&amp;gt; &lt;br/&gt;&amp;gt; &amp;gt; The threat of a SHA1 collision attack to insert a malicious pull request&lt;br/&gt;&amp;gt; &amp;gt; are tiny compared with the other threats - e.g. github being compromised,&lt;br/&gt;&amp;gt; &amp;gt; one of the core developers&amp;#39; passwords being compromised, one of the core&lt;br/&gt;&amp;gt; &amp;gt; developers going rogue, sourceforge (distribution site) being compromised&lt;br/&gt;&amp;gt; &amp;gt; etc etc... believe me there&amp;#39;s a lot more to worry about than a SHA1&lt;br/&gt;&amp;gt; &amp;gt; attack...&lt;br/&gt;&amp;gt; &amp;gt;&lt;br/&gt;&amp;gt; &amp;gt; Not meaning to scare, just to put things in perspective - this is why we&lt;br/&gt;&amp;gt; &amp;gt; all need to peer review each others commits and keep an eye out for&lt;br/&gt;&amp;gt; &amp;gt; suspicious commits, leverage the benefits of this project being open source&lt;br/&gt;&amp;gt; &amp;gt; and easily peer reviewed.&lt;br/&gt;&amp;gt; &amp;gt;&lt;br/&gt;&amp;gt; &lt;br/&gt;&amp;gt; Very good points, and I think you&amp;#39;re absolutely right.&lt;br/&gt;&amp;gt; &lt;br/&gt;&amp;gt; But just running the numbers, to get the picture, based of scheiner&amp;#39;s&lt;br/&gt;&amp;gt; statistics:&lt;br/&gt;&amp;gt; &lt;br/&gt;&amp;gt; &lt;a href=&#34;http://www.schneier.com/blog/archives/2012/10/when_will_we_se.html&#34;&gt;http://www.schneier.com/blog/archives/2012/10/when_will_we_se.html&lt;/a&gt;&lt;br/&gt;&amp;gt; &lt;br/&gt;&amp;gt; We&amp;#39;re talking about a million terrahashes = 2^60 right?&lt;br/&gt;&amp;gt; &lt;br/&gt;&amp;gt; With the block chain, you only have a 10 minute window, but with source&lt;br/&gt;&amp;gt; code you have a longer time to prepare.&lt;br/&gt;&amp;gt; &lt;br/&gt;&amp;gt; Couldnt this be done with an ASIC in about a week?&lt;br/&gt;&amp;gt; &lt;br/&gt;&amp;gt; &lt;br/&gt;&amp;gt; &lt;br/&gt;&amp;gt; &amp;gt;&lt;br/&gt;&amp;gt; &amp;gt; Will&lt;br/&gt;&amp;gt; &amp;gt;&lt;br/&gt;&amp;gt; &amp;gt;&lt;br/&gt;&amp;gt; &amp;gt; On 1 April 2013 23:52, Melvin Carvalho &amp;lt;melvincarvalho at gmail.com&amp;gt; wrote:&lt;br/&gt;&amp;gt; &amp;gt;&lt;br/&gt;&amp;gt; &amp;gt;&amp;gt;&lt;br/&gt;&amp;gt; &amp;gt;&amp;gt;&lt;br/&gt;&amp;gt; &amp;gt;&amp;gt;&lt;br/&gt;&amp;gt; &amp;gt;&amp;gt; On 1 April 2013 20:28, Petr Praus &amp;lt;petr at praus.net&amp;gt; wrote:&lt;br/&gt;&amp;gt; &amp;gt;&amp;gt;&lt;br/&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt; An attacker would have to find a collision between two specific pieces&lt;br/&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt; of code - his malicious code and a useful innoculous code that would be&lt;br/&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt; accepted as pull request. This is the second, much harder case in the&lt;br/&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt; birthday problem. When people talk about SHA-1 being broken they actually&lt;br/&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt; mean the first case in the birthday problem - find any two arbitrary values&lt;br/&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt; that hash to the same value. So, no I don&amp;#39;t think it&amp;#39;s a feasible attack&lt;br/&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt; vector any time soon.&lt;br/&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;&lt;br/&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt; Besides, with that kind of hashing power, it might be more feasible to&lt;br/&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt; cause problems in the chain by e.g. constantly splitting it.&lt;br/&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;&lt;br/&gt;&amp;gt; &amp;gt;&amp;gt;&lt;br/&gt;&amp;gt; &amp;gt;&amp;gt; OK, maybe im being *way* too paranoid here ... but what if someone had&lt;br/&gt;&amp;gt; &amp;gt;&amp;gt; access to github, could they replace one file with one they had prepared at&lt;br/&gt;&amp;gt; &amp;gt;&amp;gt; some point?&lt;br/&gt;&amp;gt; &amp;gt;&amp;gt;&lt;br/&gt;&amp;gt; &amp;gt;&amp;gt;&lt;br/&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;&lt;br/&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;&lt;br/&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt; On 1 April 2013 03:26, Melvin Carvalho &amp;lt;melvincarvalho at gmail.com&amp;gt; wrote:&lt;br/&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;&lt;br/&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;&amp;gt;  I was just looking at:&lt;br/&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;&amp;gt;&lt;br/&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;&amp;gt; &lt;a href=&#34;https://bitcointalk.org/index.php?topic=4571.0&#34;&gt;https://bitcointalk.org/index.php?topic=4571.0&lt;/a&gt;&lt;br/&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;&amp;gt;&lt;br/&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;&amp;gt; I&amp;#39;m just curious if there is a possible attack vector here based on the&lt;br/&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;&amp;gt; fact that git uses the relatively week SHA1&lt;br/&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;&amp;gt;&lt;br/&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;&amp;gt; Could a seemingly innocuous pull request generate another file with a&lt;br/&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;&amp;gt; backdoor/nonce combination that slips under the radar?&lt;br/&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;&amp;gt;&lt;br/&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;&amp;gt; Apologies if this has come up before ...&lt;br/&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;&amp;gt;&lt;br/&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;&amp;gt;&lt;br/&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;&amp;gt; ------------------------------------------------------------------------------&lt;br/&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;&amp;gt; Own the Future-Intel&amp;amp;reg; Level Up Game Demo Contest 2013&lt;br/&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;&amp;gt; Rise to greatness in Intel&amp;#39;s independent game demo contest.&lt;br/&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;&amp;gt; Compete for recognition, cash, and the chance to get your game&lt;br/&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;&amp;gt; on Steam. $5K grand prize plus 10 genre and skill prizes.&lt;br/&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;&amp;gt; Submit your demo by 6/6/13. &lt;a href=&#34;http://p.sf.net/sfu/intel_levelupd2d&#34;&gt;http://p.sf.net/sfu/intel_levelupd2d&lt;/a&gt;&lt;br/&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;&amp;gt; _______________________________________________&lt;br/&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;&amp;gt; Bitcoin-development mailing list&lt;br/&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;&amp;gt; Bitcoin-development at lists.sourceforge.net&lt;br/&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;&amp;gt; &lt;a href=&#34;https://lists.sourceforge.net/lists/listinfo/bitcoin-development&#34;&gt;https://lists.sourceforge.net/lists/listinfo/bitcoin-development&lt;/a&gt;&lt;br/&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;&amp;gt;&lt;br/&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;&amp;gt;&lt;br/&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;&lt;br/&gt;&amp;gt; &amp;gt;&amp;gt;&lt;br/&gt;&amp;gt; &amp;gt;&amp;gt;&lt;br/&gt;&amp;gt; &amp;gt;&amp;gt; ------------------------------------------------------------------------------&lt;br/&gt;&amp;gt; &amp;gt;&amp;gt; Own the Future-Intel&amp;amp;reg; Level Up Game Demo Contest 2013&lt;br/&gt;&amp;gt; &amp;gt;&amp;gt; Rise to greatness in Intel&amp;#39;s independent game demo contest.&lt;br/&gt;&amp;gt; &amp;gt;&amp;gt; Compete for recognition, cash, and the chance to get your game&lt;br/&gt;&amp;gt; &amp;gt;&amp;gt; on Steam. $5K grand prize plus 10 genre and skill prizes.&lt;br/&gt;&amp;gt; &amp;gt;&amp;gt; Submit your demo by 6/6/13. &lt;a href=&#34;http://p.sf.net/sfu/intel_levelupd2d&#34;&gt;http://p.sf.net/sfu/intel_levelupd2d&lt;/a&gt;&lt;br/&gt;&amp;gt; &amp;gt;&amp;gt; _______________________________________________&lt;br/&gt;&amp;gt; &amp;gt;&amp;gt; Bitcoin-development mailing list&lt;br/&gt;&amp;gt; &amp;gt;&amp;gt; Bitcoin-development at lists.sourceforge.net&lt;br/&gt;&amp;gt; &amp;gt;&amp;gt; &lt;a href=&#34;https://lists.sourceforge.net/lists/listinfo/bitcoin-development&#34;&gt;https://lists.sourceforge.net/lists/listinfo/bitcoin-development&lt;/a&gt;&lt;br/&gt;&amp;gt; &amp;gt;&amp;gt;&lt;br/&gt;&amp;gt; &amp;gt;&amp;gt;&lt;br/&gt;&amp;gt; &amp;gt;&lt;br/&gt;&lt;br/&gt;&amp;gt; ------------------------------------------------------------------------------&lt;br/&gt;&amp;gt; Own the Future-Intel&amp;amp;reg; Level Up Game Demo Contest 2013&lt;br/&gt;&amp;gt; Rise to greatness in Intel&amp;#39;s independent game demo contest.&lt;br/&gt;&amp;gt; Compete for recognition, cash, and the chance to get your game &lt;br/&gt;&amp;gt; on Steam. $5K grand prize plus 10 genre and skill prizes. &lt;br/&gt;&amp;gt; Submit your demo by 6/6/13. &lt;a href=&#34;http://p.sf.net/sfu/intel_levelupd2d&#34;&gt;http://p.sf.net/sfu/intel_levelupd2d&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;&amp;gt; _______________________________________________&lt;br/&gt;&amp;gt; Bitcoin-development mailing list&lt;br/&gt;&amp;gt; Bitcoin-development at lists.sourceforge.net&lt;br/&gt;&amp;gt; &lt;a href=&#34;https://lists.sourceforge.net/lists/listinfo/bitcoin-development&#34;&gt;https://lists.sourceforge.net/lists/listinfo/bitcoin-development&lt;/a&gt;
    </content>
    <updated>2023-06-07T11:42:47Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsdaf0hlkk3kc7lma08k5dqy24ac3uqyfgluv7d7v2rkk24r3k0tzczypv0zc8qm0rxzczhqjcepcm02xvl3qwgv8jnwc78q4lxhsxp8e54qv86nr4</id>
    
      <title type="html">📅 Original date posted:2013-03-13 📝 Original message:On ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsdaf0hlkk3kc7lma08k5dqy24ac3uqyfgluv7d7v2rkk24r3k0tzczypv0zc8qm0rxzczhqjcepcm02xvl3qwgv8jnwc78q4lxhsxp8e54qv86nr4" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsv59224vmtauxl0hrntpesd5nywwv3re2m70c5u3qsqswtcs55vyqlswrsy&#39;&gt;nevent1q…wrsy&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;📅 Original date posted:2013-03-13&lt;br/&gt;📝 Original message:On Wed, Mar 13, 2013 at 02:27:01PM -0700, Gregory Maxwell wrote:&lt;br/&gt;&amp;gt; On Wed, Mar 13, 2013 at 2:22 PM, Roy Badami &amp;lt;roy at gnomon.org.uk&amp;gt; wrote:&lt;br/&gt;&amp;gt; &amp;gt; The idea of the client detecting/warning about not-trivial forking&lt;br/&gt;&amp;gt; &amp;gt; seems worthwhile too, though, assuming it doesn&amp;#39;t already (AIUI it&lt;br/&gt;&amp;gt; &amp;gt; doesn&amp;#39;t).&lt;br/&gt;&amp;gt; &lt;br/&gt;&amp;gt; It does warn??? if its heard the fork and its on the lower difficulty&lt;br/&gt;&amp;gt; side. Extending that to also alert if its on the winning side and the&lt;br/&gt;&amp;gt; fork is long enough might be wise, though I have a little concern that&lt;br/&gt;&amp;gt; it&amp;#39;ll be mistaken to be more dependable than it would be.&lt;br/&gt;&lt;br/&gt;Still, it would have meant that all 0.8 users would have immediatley&lt;br/&gt;been told that something was wrong.  I don&amp;#39;t know to what extent it&lt;br/&gt;was luck that this was dealt with as promptly and efficiently as it&lt;br/&gt;was, but to the extent that luck was involved, a slew of 0.8 users&lt;br/&gt;shouting in various places &amp;#34;wtf is going on&amp;#34; couldn&amp;#39;t but help in&lt;br/&gt;reducing the element of luck if something similar were to happen again.&lt;br/&gt;&lt;br/&gt;roy
    </content>
    <updated>2023-06-07T11:39:11Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqs2n72lsv95y0k54cs6lapmwtq2aj9ys5fffj4sh9r6d2tyy20sy3czypv0zc8qm0rxzczhqjcepcm02xvl3qwgv8jnwc78q4lxhsxp8e54qj2mghv</id>
    
      <title type="html">📅 Original date posted:2013-03-13 📝 Original message:On ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqs2n72lsv95y0k54cs6lapmwtq2aj9ys5fffj4sh9r6d2tyy20sy3czypv0zc8qm0rxzczhqjcepcm02xvl3qwgv8jnwc78q4lxhsxp8e54qj2mghv" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqs2p4u907x4rcndaems6y2hr3tx7lzldxmv3c4fjjau68w236g4n9qu5t8ds&#39;&gt;nevent1q…t8ds&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;📅 Original date posted:2013-03-13&lt;br/&gt;📝 Original message:On Wed, Mar 13, 2013 at 09:14:03PM &#43;0000, Luke-Jr wrote:&lt;br/&gt;&amp;gt; On Wednesday, March 13, 2013 9:06:44 PM Andy Parkins wrote:&lt;br/&gt;&amp;gt; &amp;gt; On Wednesday 13 Mar 2013 12:56:29 Luke-Jr wrote:&lt;br/&gt;&amp;gt; &amp;gt; &amp;gt; Here&amp;#39;s a simple proposal to start discussion from...&lt;br/&gt;&amp;gt; &amp;gt; &lt;br/&gt;&amp;gt; &amp;gt; It seems to me that the biggest failure was not the development of two&lt;br/&gt;&amp;gt; &amp;gt; chains, but the assurance to users (by the client) that their transactions&lt;br/&gt;&amp;gt; &amp;gt; were confirmed.&lt;br/&gt;&amp;gt; &lt;br/&gt;&amp;gt; These are both the same thing.&lt;br/&gt;&lt;br/&gt;The idea of the client detecting/warning about not-trivial forking&lt;br/&gt;seems worthwhile too, though, assuming it doesn&amp;#39;t already (AIUI it&lt;br/&gt;doesn&amp;#39;t).&lt;br/&gt;&lt;br/&gt;I don&amp;#39;t know if there&amp;#39;s any automatic monitoring for forks, but if not&lt;br/&gt;I would assume that the core devs and/or Bitcoin Foundation would be&lt;br/&gt;planning to put some in place.  But there&amp;#39;s no reason I can see why&lt;br/&gt;end users clients should&amp;#39;t be warning of such situations, too, when&lt;br/&gt;they can (obviously they won&amp;#39;t always be aware of the fork).&lt;br/&gt;&lt;br/&gt;roy
    </content>
    <updated>2023-06-07T11:39:05Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsphu8nz3tl3lttnmjfvk06x8hj6nfxgdg9dfu5za29fvarnlrkhxczypv0zc8qm0rxzczhqjcepcm02xvl3qwgv8jnwc78q4lxhsxp8e54q2v6qhg</id>
    
      <title type="html">📅 Original date posted:2013-03-12 📝 Original message:&amp;gt; ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsphu8nz3tl3lttnmjfvk06x8hj6nfxgdg9dfu5za29fvarnlrkhxczypv0zc8qm0rxzczhqjcepcm02xvl3qwgv8jnwc78q4lxhsxp8e54q2v6qhg" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqs0w8zkm7l2rhadtnyznhe07mc0nv4p577t6gvr0u3sdl9d2gfu6yq72c7kl&#39;&gt;nevent1q…c7kl&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;📅 Original date posted:2013-03-12&lt;br/&gt;📝 Original message:&amp;gt; clients are anyway keeping, and re-relaying, their own transactions&lt;br/&gt;&amp;gt; and hence it would mean only little, and only little for clients.&lt;br/&gt;&lt;br/&gt;Not all end-user clients are always-on though
    </content>
    <updated>2023-06-07T11:37:06Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsy92mn809uruwtlyaa3294npvdctx4j0ssmgersv3frqf9evryhfczypv0zc8qm0rxzczhqjcepcm02xvl3qwgv8jnwc78q4lxhsxp8e54q4q62vd</id>
    
      <title type="html">📅 Original date posted:2012-11-29 📝 Original ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsy92mn809uruwtlyaa3294npvdctx4j0ssmgersv3frqf9evryhfczypv0zc8qm0rxzczhqjcepcm02xvl3qwgv8jnwc78q4lxhsxp8e54q4q62vd" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsflt936ma3s9gpws690jwylqc6x8dznj7kdqql29m6zjucazhfc8cxw0eq2&#39;&gt;nevent1q…0eq2&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;📅 Original date posted:2012-11-29&lt;br/&gt;📝 Original message:I&amp;#39;d still like to understand the rationale for having the merchant&lt;br/&gt;broadcast the transaction - it seems to add complexity and create edge&lt;br/&gt;cases.&lt;br/&gt;&lt;br/&gt;How about this as an alternative proposal:&lt;br/&gt;&lt;br/&gt;The buyer&amp;#39;s client prepares the transaction and computes its txid.  It&lt;br/&gt;then sends a ValidatePurchase message to the merchant containing the&lt;br/&gt;proposed Outputs and a copy of the merchant_data along with the txid.&lt;br/&gt;&lt;br/&gt;Assuming the proposed payment is accepted as valid by the merchant,&lt;br/&gt;the buyer&amp;#39;s client simply broadcasts the pre-prepared transaction in&lt;br/&gt;the normal way, and it is the merchant&amp;#39;s responsibility to watch for&lt;br/&gt;this transaction to arrive over the p2p network/blockchain to complete&lt;br/&gt;the purchase.  (So if the merchant rejects the purchase at the&lt;br/&gt;ValidatePurchase stage, they never get to see the transaction that the&lt;br/&gt;buyer prepared, and there&amp;#39;s therefore no need for a send-to-self to&lt;br/&gt;cancel it.)&lt;br/&gt;&lt;br/&gt;An optional RequestReceipt message (perhaps containing the&lt;br/&gt;merchant_data and txid) can be sent by the client after the&lt;br/&gt;transaction has been broadcast - but by making this explicitly&lt;br/&gt;optional it forces the merchant to rely on seeing the bitcoin&lt;br/&gt;transaction to &amp;#39;commit&amp;#39; the payment and not on the RequestReceipt&lt;br/&gt;message.&lt;br/&gt;&lt;br/&gt;As far as I can see this proposal has no edge cases where the buyer&lt;br/&gt;and merchant have differing ideas as to whether the transaction has&lt;br/&gt;&amp;#39;comitted&amp;#39; - or at least, no more edge cases than the standard bitcoin&lt;br/&gt;protocol has.&lt;br/&gt;&lt;br/&gt;roy
    </content>
    <updated>2023-06-07T10:42:01Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqs8wpvyyxg6l4qsk3x7ylytp99kt0j9csqcenlqzgyq2nv0gf28pkqzypv0zc8qm0rxzczhqjcepcm02xvl3qwgv8jnwc78q4lxhsxp8e54qkygdsf</id>
    
      <title type="html">📅 Original date posted:2012-11-28 📝 Original message:&amp;gt; ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqs8wpvyyxg6l4qsk3x7ylytp99kt0j9csqcenlqzgyq2nv0gf28pkqzypv0zc8qm0rxzczhqjcepcm02xvl3qwgv8jnwc78q4lxhsxp8e54qkygdsf" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsy3g7n64mw6adr9vthcr0u0nc3cuk9mq0e0ajznc7g2p8e05arsssekgjqd&#39;&gt;nevent1q…gjqd&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;📅 Original date posted:2012-11-28&lt;br/&gt;📝 Original message:&amp;gt; If a Receipt is not received for any reason (timeout, error) and&lt;br/&gt;&amp;gt; Payment.transactions has not been broadcast by the merchant on the&lt;br/&gt;&amp;gt; Bitcoin p2p network, then the Bitcoin client should assume that the&lt;br/&gt;&amp;gt; payment failed, inform the customer that the payment failed, and&lt;br/&gt;&amp;gt; return coins involved in the transaction to the customer&amp;#39;s wallet.&lt;br/&gt;&lt;br/&gt;I&amp;#39;m not sure I understand the rationale for this.  In the above&lt;br/&gt;scenario the buyer has no way to determine whether the merchant still&lt;br/&gt;has a copy of the transaction that they could broadcast in future.&lt;br/&gt;Maybe there is simply a systems problem at the merchant which has&lt;br/&gt;temporarily delayed the transaction broadcast. Or maybe a dishonest&lt;br/&gt;merchant deliberately engineered this situation in an attempt to&lt;br/&gt;mislead the buyer as to the status of their payment.&lt;br/&gt;&lt;br/&gt;Either way, having the buyer think the coins have been returned to&lt;br/&gt;their wallet - only to disappear from their wallet again at some later&lt;br/&gt;time - would seriously damage user confidence in Bitcoin IMHO.&lt;br/&gt;&lt;br/&gt;It seems to me that the first thing the buyer should do given the&lt;br/&gt;protocol as it stands is simply resend the Payment message - if there&lt;br/&gt;was a temporary problem then resending the payment message (with the&lt;br/&gt;same signed transation) might resolve the sitution.&lt;br/&gt;&lt;br/&gt;If after several retries the status of the transaction is still&lt;br/&gt;undefined then it&amp;#39;s really not clear what to do, but it seems&lt;br/&gt;desireable to have the client take steps so that it can return to a&lt;br/&gt;state of certainly about its wallet balance as quickly as possible.&lt;br/&gt;Two things I can imagine that the buyer might want their client to do&lt;br/&gt;at this point are:&lt;br/&gt;&lt;br/&gt; * broadcast the transaction itself, so they are sure the payment&lt;br/&gt;   transaction will make it into the blockchain without any further&lt;br/&gt;   action on their part, or&lt;br/&gt;&lt;br/&gt; * invalidate the transaction by immediately broadcasting a&lt;br/&gt;   pay-to-self transaction that spends one or more of the same outputs&lt;br/&gt;   that the payment transaction spends (and treat the funds as part of&lt;br/&gt;   the unconfirmed balance until this pay-to-self transaction&lt;br/&gt;   confirms).  This ensures the merchant can&amp;#39;t subsequently use a&lt;br/&gt;   transaction which the buyer thinks has failed&lt;br/&gt;&lt;br/&gt;It seems to me it would be simpler and cleaner if the buyer just&lt;br/&gt;always broadcasted the transaction on the p2p network, regardless of&lt;br/&gt;whether the Invoice includes a receiptURI.  If a receiptURI is&lt;br/&gt;included, the buyer&amp;#39;s client would also include the transaction in the&lt;br/&gt;Purchase message.  The merchant then tries to broadcast the&lt;br/&gt;transaction as well (unless their bitcoind has already seen it, which&lt;br/&gt;may well be the common case).  This approach seems to me to have fewer&lt;br/&gt;nasty edge cases.s&lt;br/&gt;&lt;br/&gt;roy
    </content>
    <updated>2023-06-07T10:41:48Z</updated>
  </entry>

</feed>