{"type":"rich","version":"1.0","author_name":"npub1pa6l5jatv92d4vzk566r58zjawpuu0we8nhrywfhp90f9948e0tsx3rxtp","author_url":"https://nostr.ae/npub1pa6l5jatv92d4vzk566r58zjawpuu0we8nhrywfhp90f9948e0tsx3rxtp","provider_name":"njump","provider_url":"https://nostr.ae","html":"📅 Original date posted:2014-04-04\n📝 Original message:\u003e Using a bitcoin address repeatedly is something we're trying to move away\nfrom.\n\nThis is indeed a flaw of the proposed protocol. However it really depends\nin the end of the usage : you could use an auth just once, to redeem a good\nyou paid, or multiple times if this makes a sense (mining pool app for\ninstance).\n\n\u003e And using a bitcoin address as a persistent identity key feels like the\nwrong direction to me.\n\nWhat would be really the difference between artificially create a\ncertificate for identity and selecting one address for identity?\n\n\u003e Better to use something like client certificates, the FIDO alliance's\n(new!) specs:\n\u003e   http://fidoalliance.org/specifications/download\n\u003e ... or Steve Gibson's proposed SQRL system:\n\u003e   https://www.grc.com/sqrl/sqrl.htm\n\nThe proposal is nothing more than sqrl scoped to Bitcoin keys.\n\n\u003e If one of those systems gets critical mass and actually starts being\nsuccessful, then I think it would make sense to specify a standard way of\nusing a HD wallet's deterministic seed to derive a key used for the FIDO or\nSQRL systems.\n\nThis could be a very interesting approach. But I think the system which\nwould get critical mass is the one which would be implemented into major\nBitcoin wallets.\n\nWhy adding another app or software when you already have all you need?\n\n\u003e\n\u003e\n\u003e\n\u003e\n\u003e On Fri, Apr 4, 2014 at 9:22 AM, Eric Larchevêque \u003celarch at gmail.com\u003e wrote:\n\u003e\u003e\n\u003e\u003e What I'm trying to achieve, is to have a very simple way of\nauthenticating yourself with one Bitcoin address from your wallet.\n\u003e\u003e For most of the people using Bitcoin, their wallet is on their phone.\n\u003e\u003e\n\u003e\u003e The UX is clear and simple :\n\u003e\u003e 1. click on \"connect with Bitcoin\" (the audience is normal people)\n\u003e\u003e 2. flash the QRcode with your wallet (blockchain.info, mycelium, ...)\n\u003e\u003e 3. accept the authentication request (same style than OpenID or Facebook\nconnect)\n\u003e\u003e 4. user is autologged and identified by the chosen Bitcoin public address\n\u003e\u003e\n\u003e\u003e It makes sense only if major wallets are supporting the protocol. If you\nneed to install a plugin or download a third party software, no one will do\nit.\n\u003e\u003e I see only benefits for the entire ecosystem, and if I'm working on such\na proposition it is because I really need this feature.\n\u003e\u003e\n\u003e\u003e Of course, it can be done without a BIP, I just need to convince wallet\ndeveloppers one by one to implement the feature.\n\u003e\u003e But I thought it was much better to start the \"official\" way, so all\nwallet could easily find and implement the same authentication mechanism.\n\u003e\u003e\n\u003e\u003e \u003e  Bitcoin and website authentication are unrelated problems\n\u003e\u003e\n\u003e\u003e I respectfully disagree. Many services require your Bitcoin address, and\nto do that they artificially request an email/password to store it.\n\u003e\u003e This is not about authentication as an identity (as \"I'm Eric\nLarcheveque\"), but as in \"I'm proving to you that I control this address\".\n\u003e\u003e\n\u003e\u003e Without such a standard protocol, you could never envision a pure\nBitcoin physical locker rental, or booking an hotel room via Bitcoin and\nopening the door through the paying address.\n\u003e\u003e\n\u003e\u003e Eric\n\u003e\u003e\n\u003e\u003e\n\u003e\u003e\n\u003e\u003e On Fri, Apr 4, 2014 at 3:08 PM, Mike Hearn \u003cmike at plan99.net\u003e wrote:\n\u003e\u003e\u003e\n\u003e\u003e\u003e This comes up every few months. I think the problem you are trying to\nsolve is already solved by SSL client certificates, and if you want to help\nmake them more widespread the programs you need to upgrade are web browsers\nand not Bitcoin wallets. There are certainly bits of infrastructure you\ncould reuse here and there, like perhaps a TREZOR with a custom firmware\nextension for really advanced/keen users, but overall Bitcoin and website\nauthentication are unrelated problems.\n\u003e\u003e\u003e\n\u003e\u003e\u003e\n\u003e\u003e\u003e On Fri, Apr 4, 2014 at 2:15 PM, Eric Larchevêque \u003celarch at gmail.com\u003e\nwrote:\n\u003e\u003e\u003e\u003e\n\u003e\u003e\u003e\u003e Hello,\n\u003e\u003e\u003e\u003e\n\u003e\u003e\u003e\u003e I've written a draft BIP description of an authentication protocol\nbased on Bitcoin public address.\n\u003e\u003e\u003e\u003e\n\u003e\u003e\u003e\u003e By authentication we mean to prove to a service/application that we\ncontrol a specific Bitcoin address by signing a challenge, and that all\nrelated data and settings may securely be linked to our session.\n\u003e\u003e\u003e\u003e\n\u003e\u003e\u003e\u003e The aim is to greatly facilitate sign ups and logins to services and\napplications, improving the Bitcoin ecosystem as a whole.\n\u003e\u003e\u003e\u003e\n\u003e\u003e\u003e\u003e https://github.com/bitid/bitid/blob/master/BIP_draft.md\n\u003e\u003e\u003e\u003e\n\u003e\u003e\u003e\u003e Demo website :\n\u003e\u003e\u003e\u003e http://bitid-demo.herokuapp.com/\n\u003e\u003e\u003e\u003e\n\u003e\u003e\u003e\u003e Classical password authentication is an insecure process that could be\nsolved with public key cryptography. The problem is that it theoretically\noffloads a lot of complexity and responsibility on the user. Managing\nprivate keys securely is complex. However this complexity is already being\naddressed in the Bitcoin ecosystem. So doing public key authentication is\npractically a free lunch to bitcoiners.\n\u003e\u003e\u003e\u003e\n\u003e\u003e\u003e\u003e I've formatted the protocol description as a BIP because this is the\nonly way to have all major wallets implementing it, and because it\ncompletely fits in my opinion the BIP \"process\" category.\n\u003e\u003e\u003e\u003e\n\u003e\u003e\u003e\u003e Please read it and let me know your thoughts and comments so we can\nimprove on this draft.\n\u003e\u003e\u003e\u003e\n\u003e\u003e\u003e\u003e Eric Larcheveque\n\u003e\u003e\u003e\u003e elarch at gmail.com\n\u003e\u003e\u003e\u003e\n\u003e\u003e\u003e\u003e\n\u003e\u003e\u003e\u003e\n------------------------------------------------------------------------------\n\u003e\u003e\u003e\u003e\n\u003e\u003e\u003e\u003e _______________________________________________\n\u003e\u003e\u003e\u003e Bitcoin-development mailing list\n\u003e\u003e\u003e\u003e Bitcoin-development at lists.sourceforge.net\n\u003e\u003e\u003e\u003e https://lists.sourceforge.net/lists/listinfo/bitcoin-development\n\u003e\u003e\u003e\u003e\n\u003e\u003e\u003e\n\u003e\u003e\n\u003e\u003e\n\u003e\u003e\n------------------------------------------------------------------------------\n\u003e\u003e\n\u003e\u003e _______________________________________________\n\u003e\u003e Bitcoin-development mailing list\n\u003e\u003e Bitcoin-development at lists.sourceforge.net\n\u003e\u003e https://lists.sourceforge.net/lists/listinfo/bitcoin-development\n\u003e\u003e\n\u003e\n\u003e\n\u003e\n\u003e --\n\u003e --\n\u003e Gavin Andresen\n-------------- next part --------------\nAn HTML attachment was scrubbed...\nURL: \u003chttp://lists.linuxfoundation.org/pipermail/bitcoin-dev/attachments/20140404/f2c5cf7a/attachment.html\u003e"}
