{"type":"rich","version":"1.0","author_name":"npub1xz8q68hmzur6c6uje593nscy3q4njx05h4vnxmz2wxxptx7u7casl2925u","author_url":"https://nostr.ae/npub1xz8q68hmzur6c6uje593nscy3q4njx05h4vnxmz2wxxptx7u7casl2925u","provider_name":"njump","provider_url":"https://nostr.ae","html":"📅 Original date posted:2011-12-16\n🗒️ Summary of this message: Various proposals for linking Bitcoin addresses to domain names or aliases have limitations, including centralization, reliance on HTTPS and CA, and DNSSEC requirements. Namecoin is a potential solution.\n📝 Original message:On Fri, Dec 16, 2011 at 1:52 PM, Khalahan \u003ckhal at dot-bit.org\u003e wrote:\n\u003e The number of proposals is not infinite, here are their problems :\n\u003e\n\u003e - FirstBits : centralized\n\u003e - DNS TXT Records : DNSSEC is required to have a minimum of security, limits\n\u003e usage to engineers, limits usage to some domain names (i won't be able to\n\u003e use a gmail address for example, because i don't control the gmail.com\n\u003e domain)\n\nThe same goes for http(s) one would not be able to use\nhttp://google.com/user unless google offers the services.\n\nALSO look at DANE for getting around the certificate requirement for https\n\n\u003e - Server Service (DNS + a daemon) : Same as DNS TXT records\n\nDNS TXT are not the only way forward, also registry/registrars can facilitate.\n\n\u003e - HTTPS Web service : relies on HTTPS and CA, bitcoin needs to be able to\n\u003e check the full certificate chain and access a list of up-to-date certificate\n\u003e authorities (installed on the OS or provided with bitcoin). And don't forget\n\u003e the CA model is not 100% reliable (several CA hacked this year + possible\n\u003e government control...).\n\nThis most likely relies on a paid, valid certificate (that expires),\nno self signed certs. I admit that running a secured https server with\na valid CA signed  cet is as simple/hard as running a DNSSEC authority\nzone.\n\nusing a x.509 certificate to secure a bitcoin transaction removes some\nof the anonymity of the transaction by allowing the lookup to identify\nthe certification, ca, crl etc thus connecting a transaction/bitcoin\naddress to the cert and to its issuing authority. No matter the\nfrequency of the destination bitcoin address changing.\n\nIMNSHO, leveraging CAs to secure http to provide a lookup translation\nto a bitcoin address will only erode anonymity. While DNS is connected\nto whois there are provision for hiding behind a proxy where to the\nbest of my knowledge there are no such provisions offered by CA's\nissuing x.509 certificates.\n\nShould self signed cers be \"allowed\" or encouraged only decreases\nsecurity. Clearly DANE would be the only way to mitigate this\nsituation but then you are back to relying on DNSSEC to bind the x.509\ncert.\n\nwash, rinse,  ...\n\n-rick\n\n\u003e - IP Transactions : This proposal seeks to enable DNS lookups for IP\n\u003e transactions =\u003e same as above\n\u003e\n\u003e I know that providing a namecoin daemon with bitcoin is not the lighter\n\u003e solution, but, if a better one existed i guess it would have already been\n\u003e integrated into bitcoin... (see in what state is my first attempt with the\n\u003e HTTPS proposal : Send payments to emails, urls and domains in GUI - khalahan\n\u003e opened this pull request April 20, 2011)\n\u003e\n\u003e So, what's next ?\n\u003e\n\u003e Le 16/12/2011 20:54, slush a écrit :\n\u003e\n\u003e Khalahan, honestly, using namecoin for aliases is (for me) clean example of\n\u003e over-engineering. I mean - it will definitely work if implemented properly.\n\u003e I played with a namecoin a bit (as my pool was the first 'big' pool\n\u003e supporting merged mining), but I think there's really long way to provide\n\u003e such alias system in namecoin and *cleanly integrate it with bitcoin*. Don't\n\u003e forget that people who want to do lookup need to maintain also namecoin\n\u003e blockchain with their bitcoin client. It goes against my instinct of keeping\n\u003e stuff easy.\n\u003e\n\u003e For example, yesterday I implemented HTTPS lookup for addresses into my fork\n\u003e of Electrum client. I did it in 15 minutes, it works as expected, it does\n\u003e the job and the implementation is really transparent, becuase implementation\n\u003e is 20 lines of code. There's no magic transformation, no forced \"?handle=\"\n\u003e parameters or whatever. And I don't care if somebody provide URL\n\u003e https://some.strange.domain/name-of-my-dog?myhandle=5678iop\u0026anything_else=True\n\u003e\n\u003e And everybody can do the same in their clients, in their merchant solutions,\n\u003e websites or whatever. Everybody can do HTTPS lookup. But try to explain DNS,\n\u003e Namecoin, IIBAN, email aliases to other programmers...\n\u003e\n\u003e Those IIBAN - well, why not. At least I see the potential in PR. So far I\n\u003e understand it as some teoretic concept which is not supported by anything\n\u003e else right now. Give it few years until it matures and then add IIBAN alias\n\u003e to Bitcoin client too.\n\u003e\n\u003e Maybe I'm repeating myself already, but the way to go is to make aliases as\n\u003e easy as possible, so everybody can implement it in their own solution and\n\u003e thus practially remove the need of using standard bitcoin addresses for\n\u003e normal users. Using some superior technology, which is hard to implement or\n\u003e even understand won't solve the situation, because it will ends up with some\n\u003e reference implementation in standard client only and nobody else will use\n\u003e it.\n\u003e\n\u003e slush\n\u003e\n\u003e\n\u003e --\n\u003e Best Regards,\n\u003e Khalahan\n\u003e http://dot-bit.org/\n\u003e\n\u003e\n\u003e ------------------------------------------------------------------------------\n\u003e Learn Windows Azure Live!  Tuesday, Dec 13, 2011\n\u003e Microsoft is holding a special Learn Windows Azure training event for\n\u003e developers. It will provide a great way to learn Windows Azure and what it\n\u003e provides. You can attend the event by watching it streamed LIVE online.\n\u003e Learn more at http://p.sf.net/sfu/ms-windowsazure\n\u003e _______________________________________________\n\u003e Bitcoin-development mailing list\n\u003e Bitcoin-development at lists.sourceforge.net\n\u003e https://lists.sourceforge.net/lists/listinfo/bitcoin-development\n\u003e"}
