{"type":"rich","version":"1.0","author_name":"npub1kf0ppcjaguxekg24yx6smgxlu73qn0k8lm0t2wrqc0scpl7u3sgsmf3f58","author_url":"https://nostr.ae/npub1kf0ppcjaguxekg24yx6smgxlu73qn0k8lm0t2wrqc0scpl7u3sgsmf3f58","provider_name":"njump","provider_url":"https://nostr.ae","html":"📅 Original date posted:2014-09-12\n📝 Original message:Indeed -- Every byte added to the QR code makes it more difficult to\nbe used in restaurants, pubs and other low-light conditions.  BitPay\ntested some of these scenarios.\n\nScannability is absolutely impacted.\n\nOn Fri, Sep 12, 2014 at 9:49 AM, Mike Hearn \u003cmike at plan99.net\u003e wrote:\n\u003e A few thoughts on this:\n\u003e\n\u003e (1) Base64 of SHA256 seems overkill. 256 bits of hash is a lot. The risk\n\u003e here is that a MITM intercepts the payment request, which will be typically\n\u003e requested just seconds after the QR code is vended. 80 bits of entropy would\n\u003e still be a lot and take a long time to brute force, whilst keeping QR codes\n\u003e more compact, which impacts scannability.\n\u003e\n\u003e (2) This should not be necessary in the common HTTPS context. The QR code\n\u003e itself is going to be fetched from some service, over HTTPS. I see no\n\u003e reasonable attacker that can MITM the request for the BIP70 message but not\n\u003e the request to get the QR code. Adding a hash makes QR codes more bloated\n\u003e and harder to scan, all on the assumption that HTTPS is broken in some odd\n\u003e way that we haven't actually ever seen in practice.\n\u003e\n\u003e (3) This can be useful in the Bluetooth context, but then again, we could\n\u003e also do things a different way by signing with the key in the first part of\n\u003e the URI, thus avoiding the need for a hash.\n\u003e\n\u003e I know I've been around the loop on this one with Andreas many times. But\n\u003e this BIP doesn't fix any actually existing problem in the previous spec. It\n\u003e exists because Andreas thinks SSL is useless. If SSL is useless we all have\n\u003e much bigger problems.\n\u003e\n\u003e ------------------------------------------------------------------------------\n\u003e Want excitement?\n\u003e Manually upgrade your production database.\n\u003e When you want reliability, choose Perforce\n\u003e Perforce version control. Predictably reliable.\n\u003e http://pubads.g.doubleclick.net/gampad/clk?id=157508191\u0026iu=/4140/ostg.clktrk\n\u003e _______________________________________________\n\u003e Bitcoin-development mailing list\n\u003e Bitcoin-development at lists.sourceforge.net\n\u003e https://lists.sourceforge.net/lists/listinfo/bitcoin-development\n\u003e\n\n\n\n-- \nJeff Garzik\nBitcoin core developer and open source evangelist\nBitPay, Inc.      https://bitpay.com/"}
