{"type":"rich","version":"1.0","author_name":"npub1tjephawh7fdf6358jufuh5eyxwauzrjqa7qn50pglee4tayc2ntqcjtl6r","author_url":"https://nostr.ae/npub1tjephawh7fdf6358jufuh5eyxwauzrjqa7qn50pglee4tayc2ntqcjtl6r","provider_name":"njump","provider_url":"https://nostr.ae","html":"📅 Original date posted:2011-12-18\n🗒️ Summary of this message: Using DNS-based alias systems for Bitcoin payments is vulnerable to spoofing. One solution is to embed a Bitcoin address in the identification string itself.\n📝 Original message:On Mon, Dec 19, 2011 at 12:58:37AM +0100, slush wrote:\n\u003e Maybe I'm retarded, but where's the point in providing alliases containing\n\u003e yet another hash in URL?\n\nAny DNS-based alias system is vulnerable to spoofing. If I can make people's\nDNS server believe that mining.cz points to my IP, I'll receive payments to\nyou...\n\nIf no trusted CA is used to authenticate the communication, there is no way\nto be sure the one you are asking how to pay, is the person you want to pay.\nTherefore, one solution is to put a bitcoin address in the identification\nstring itself, and requiring SSL communication authenticated using the\nrespective key.\n\nThis makes the identification strings obviously less useful as aliases,\nbut pure aliases in the sense of human-typable strings have imho\nlimited usefulness anyway - in most cases these identification strings\nwill be communicated through other electronic means anyway.\n\nFurthermore, the embedded bitcoin address could be hidden from the user:\nretrieved when first connecting, and stored together with the URI in\nan address book. Like ssh, it could warn the user if the key changes\n(which wil be ignored by most users anyway, but what do you do about\nthat?)\n\n-- \nPieter"}
