{"type":"rich","version":"1.0","author_name":"npub1trckpcxmceskq4cykxgwxm63n8ugrjrpu5mk83c90e4upsf7d9gqf0f95j","author_url":"https://nostr.ae/npub1trckpcxmceskq4cykxgwxm63n8ugrjrpu5mk83c90e4upsf7d9gqf0f95j","provider_name":"njump","provider_url":"https://nostr.ae","html":"📅 Original date posted:2015-02-05\n📝 Original message:Personally I like the simplicity of tapping two phones together to\nmake payment - it should be quicker and easier than scanning QR codes\nand it's a trust model that's hard to misunderstand.\n\nIs NFC good enough for that?  I fear even with NFC it is possible to\nproduce a device with longer range than one would expect.  What\nhappened to the idea of tapping two devices together and then\ncomparing the timing of the tap (as detected by the phones'\naccelerometers) to make spoofing a transaction harder?  I remember\nhearing about that years ago - is that still a thing?\n\nroy\n\nOn Thu, Feb 05, 2015 at 02:10:51PM -0800, Eric Voskuil wrote:\n\u003e A MITM can receive the initial broadcast and then spoof it by jamming the original. You then only see one.\n\u003e \n\u003e e\n\u003e \n\u003e \u003e On Feb 5, 2015, at 2:07 PM, Paul Puey \u003cpaul at airbitz.co\u003e wrote:\n\u003e \u003e \n\u003e \u003e So if you picked up the BLE broadcast request. All you know is that *someone* within 100m is requesting bitcoin at a certain address. Not necessarily who. The *name* is both optional, and possibly just a *handle* of the user. If I'm sitting 5 ft away from someone at dinner and wanted to pay them via BLE, I might see \"Monkey Dude\" on my list and simply ask him \"is that you?\" If so, I send it. If there are two \"Monkey Dude's\" Then I have to bother with the address prefix, but not otherwise.\n\u003e \u003e \n\u003e \u003e\u003e On Thu, Feb 5, 2015 at 1:46 PM, Eric Voskuil \u003ceric at voskuil.org\u003e wrote:\n\u003e \u003e\u003e BLE has an advertised range of over 100m. \n\u003e \u003e\u003e \n\u003e \u003e\u003e http://www.bluetooth.com/Pages/low-energy-tech-info.aspx\n\u003e \u003e\u003e \n\u003e \u003e\u003e In the case of mass surveillance that range could most likely be extended dramatically by the reviewer. I've seen  WiFi ranges of over a mile with a strong (not FCC approved) receiver.\n\u003e \u003e\u003e \n\u003e \u003e\u003e WiFi hotspots don't have strong identity or a guaranteed position, so they can't be trusted for location.\n\u003e \u003e\u003e \n\u003e \u003e\u003e e\n\u003e \u003e\u003e \n\u003e \u003e\u003e On Feb 5, 2015, at 1:36 PM, Mike Hearn \u003cmike at plan99.net\u003e wrote:\n\u003e \u003e\u003e \n\u003e \u003e\u003e\u003e\u003e This sounds horrible. You could basically monitor anyone with a wallet in a highly populated area and track them super easily by doing facial recognition.\n\u003e \u003e\u003e\u003e \n\u003e \u003e\u003e\u003e We're talking about BLE, still? The radio tech that runs in the so called \"junk bands\" because propagation is so poor?\n\u003e \u003e\u003e\u003e \n\u003e \u003e\u003e\u003e My watch loses its connection to my phone if I just put it down and walk around my apartment. I'm all for reasonable paranoia, but Bluetooth isn't going to be enabling mass surveillance any time soon. It barely goes through air, let alone walls.\n\u003e \u003e\u003e\u003e \n\u003e \u003e\u003e\u003e Anyway, whatever. I'm just bouncing around ideas for faster user interfaces. You could always switch it off or set it to be triggered by the presence of particular wifi hotspots, if you don't mind an initial bit of setup.\n\u003e \u003e\u003e\u003e \n\u003e \u003e\u003e\u003e Back on topic - the debate is interesting, but I think to get this to the stage of being a BIP we'd need at least another wallet to implement it? Then I guess a BIP would be useful regardless of the design issues. The prefix matching still feels flaky to me but it's hard to know if you could really swipe payments out of the air in practice, without actually trying it.\n\u003e \u003e \n\n\u003e ------------------------------------------------------------------------------\n\u003e Dive into the World of Parallel Programming. The Go Parallel Website,\n\u003e sponsored by Intel and developed in partnership with Slashdot Media, is your\n\u003e hub for all things parallel software development, from weekly thought\n\u003e leadership blogs to news, videos, case studies, tutorials and more. Take a\n\u003e look and join the conversation now. http://goparallel.sourceforge.net/\n\n\u003e _______________________________________________\n\u003e Bitcoin-development mailing list\n\u003e Bitcoin-development at lists.sourceforge.net\n\u003e https://lists.sourceforge.net/lists/listinfo/bitcoin-development"}
