{"type":"rich","version":"1.0","author_name":"npub1m6p5kgcd428x6pxyfege98zjmlwrdhp0gyz6pdnsvrvalscddnxqurdjn5","author_url":"https://nostr.ae/npub1m6p5kgcd428x6pxyfege98zjmlwrdhp0gyz6pdnsvrvalscddnxqurdjn5","provider_name":"njump","provider_url":"https://nostr.ae","html":"📅 Original date posted:2014-04-07\n📝 Original message:I have to play dissenter here again..\n\nUsing a bitcoin address as a persistent identity key is the first real-world\nuse of Bitcoin that I can imagine will make it a 'killer app' that everyone\nand their grandma will want to use.\n\nIf you think 'certificates' are a good solution, then there is some way in\nwhich we have dramatically divergent goals.\n\nI like distributed, decentralized systems in which anyone can download the \ncode and be free to participate in the things they want to securely and \nreliably.\n\nAs soon as I hear 'certificate', I see a system in which one must pay at toll\nto speak, and which puts the listeners at risk because a certificate issuer\nis such a high-value target for malicious attack.\n\nSelf-signed certificates are great for techno-wizards, but grandma has no\nidea if the self-signed cert was signed by her grandson, or by the hacker\ntrying to redirect her social security check.\n\n\"This is your bitcoin address, it's your money AND your key to log into \nyour bank website securely, so don't lose it. If you want our address\nprotection insurance service that will be $20 per month, and if you do lose\nit, we'll fix it. If you keep losing it, then your rates will go up, just \nlike car insurance if you keep crashing\"\n\n\nOn Fri, Apr 04, 2014 at 09:32:40AM -0400, Gavin Andresen wrote:\n\u003e Using a bitcoin address repeatedly is something we're trying to move away\n\u003e from.\n\u003e \n\u003e And using a bitcoin address as a persistent identity key feels like the\n\u003e wrong direction to me.\n\u003e \n\u003e Better to use something like client certificates, the FIDO alliance's\n\u003e (new!) specs:\n\u003e   http://fidoalliance.org/specifications/download\n\u003e \n\u003e ... or Steve Gibson's proposed SQRL system:\n\u003e   https://www.grc.com/sqrl/sqrl.htm\n\u003e \n\u003e If one of those systems gets critical mass and actually starts being\n\u003e successful, then I think it would make sense to specify a standard way of\n\u003e using a HD wallet's deterministic seed to derive a key used for the FIDO or\n\u003e SQRL systems.\n\u003e \n\u003e \n\u003e \n\u003e \n\u003e On Fri, Apr 4, 2014 at 9:22 AM, Eric Larchevêque \u003celarch at gmail.com\u003e wrote:\n\u003e \n\u003e \u003e What I'm trying to achieve, is to have a very simple way of authenticating\n\u003e \u003e yourself with one Bitcoin address from your wallet.\n\u003e \u003e For most of the people using Bitcoin, their wallet is on their phone.\n\u003e \u003e\n\u003e \u003e The UX is clear and simple :\n\u003e \u003e 1. click on \"connect with Bitcoin\" (the audience is normal people)\n\u003e \u003e 2. flash the QRcode with your wallet (blockchain.info, mycelium, ...)\n\u003e \u003e 3. accept the authentication request (same style than OpenID or Facebook\n\u003e \u003e connect)\n\u003e \u003e 4. user is autologged and identified by the chosen Bitcoin public address\n\u003e \u003e\n\u003e \u003e It makes sense only if major wallets are supporting the protocol. If you\n\u003e \u003e need to install a plugin or download a third party software, no one will do\n\u003e \u003e it.\n\u003e \u003e I see only benefits for the entire ecosystem, and if I'm working on such a\n\u003e \u003e proposition it is because I really need this feature.\n\u003e \u003e\n\u003e \u003e Of course, it can be done without a BIP, I just need to convince wallet\n\u003e \u003e developpers one by one to implement the feature.\n\u003e \u003e But I thought it was much better to start the \"official\" way, so all\n\u003e \u003e wallet could easily find and implement the same authentication mechanism.\n\u003e \u003e\n\u003e \u003e \u003e  Bitcoin and website authentication are unrelated problems\n\u003e \u003e\n\u003e \u003e I respectfully disagree. Many services require your Bitcoin address, and\n\u003e \u003e to do that they artificially request an email/password to store it.\n\u003e \u003e This is not about authentication as an identity (as \"I'm Eric\n\u003e \u003e Larcheveque\"), but as in \"I'm proving to you that I control this address\".\n\u003e \u003e\n\u003e \u003e Without such a standard protocol, you could never envision a pure Bitcoin\n\u003e \u003e physical locker rental, or booking an hotel room via Bitcoin and opening\n\u003e \u003e the door through the paying address.\n\u003e \u003e\n\u003e \u003e Eric\n\u003e \u003e\n\u003e \u003e\n\u003e \u003e\n\u003e \u003e On Fri, Apr 4, 2014 at 3:08 PM, Mike Hearn \u003cmike at plan99.net\u003e wrote:\n\u003e \u003e\n\u003e \u003e\u003e This comes up every few months. I think the problem you are trying to\n\u003e \u003e\u003e solve is already solved by SSL client certificates, and if you want to help\n\u003e \u003e\u003e make them more widespread the programs you need to upgrade are web browsers\n\u003e \u003e\u003e and not Bitcoin wallets. There are certainly bits of infrastructure you\n\u003e \u003e\u003e could reuse here and there, like perhaps a TREZOR with a custom firmware\n\u003e \u003e\u003e extension for really advanced/keen users, but overall Bitcoin and website\n\u003e \u003e\u003e authentication are unrelated problems.\n\u003e \u003e\u003e\n\u003e \u003e\u003e\n\u003e \u003e\u003e On Fri, Apr 4, 2014 at 2:15 PM, Eric Larchevêque \u003celarch at gmail.com\u003ewrote:\n\u003e \u003e\u003e\n\u003e \u003e\u003e\u003e Hello,\n\u003e \u003e\u003e\u003e\n\u003e \u003e\u003e\u003e I've written a draft BIP description of an authentication protocol based\n\u003e \u003e\u003e\u003e on Bitcoin public address.\n\u003e \u003e\u003e\u003e\n\u003e \u003e\u003e\u003e By authentication we mean to prove to a service/application that we\n\u003e \u003e\u003e\u003e control a specific Bitcoin address by signing a challenge, and that all\n\u003e \u003e\u003e\u003e related data and settings may securely be linked to our session.\n\u003e \u003e\u003e\u003e\n\u003e \u003e\u003e\u003e The aim is to greatly facilitate sign ups and logins to services and\n\u003e \u003e\u003e\u003e applications, improving the Bitcoin ecosystem as a whole.\n\u003e \u003e\u003e\u003e\n\u003e \u003e\u003e\u003e https://github.com/bitid/bitid/blob/master/BIP_draft.md\n\u003e \u003e\u003e\u003e\n\u003e \u003e\u003e\u003e Demo website :\n\u003e \u003e\u003e\u003e http://bitid-demo.herokuapp.com/\n\u003e \u003e\u003e\u003e\n\u003e \u003e\u003e\u003e Classical password authentication is an insecure process that could be\n\u003e \u003e\u003e\u003e solved with public key cryptography. The problem is that it theoretically\n\u003e \u003e\u003e\u003e offloads a lot of complexity and responsibility on the user. Managing\n\u003e \u003e\u003e\u003e private keys securely is complex. However this complexity is already being\n\u003e \u003e\u003e\u003e addressed in the Bitcoin ecosystem. So doing public key authentication is\n\u003e \u003e\u003e\u003e practically a free lunch to bitcoiners.\n\u003e \u003e\u003e\u003e\n\u003e \u003e\u003e\u003e I've formatted the protocol description as a BIP because this is the\n\u003e \u003e\u003e\u003e only way to have all major wallets implementing it, and because it\n\u003e \u003e\u003e\u003e completely fits in my opinion the BIP \"process\" category.\n\u003e \u003e\u003e\u003e\n\u003e \u003e\u003e\u003e Please read it and let me know your thoughts and comments so we can\n\u003e \u003e\u003e\u003e improve on this draft.\n\u003e \u003e\u003e\u003e\n\u003e \u003e\u003e\u003e Eric Larcheveque\n\u003e \u003e\u003e\u003e elarch at gmail.com\n\u003e \u003e\u003e\u003e\n\u003e \u003e\u003e\u003e\n\u003e \u003e\u003e\u003e\n\u003e \u003e\u003e\u003e ------------------------------------------------------------------------------\n\u003e \u003e\u003e\u003e\n\u003e \u003e\u003e\u003e _______________________________________________\n\u003e \u003e\u003e\u003e Bitcoin-development mailing list\n\u003e \u003e\u003e\u003e Bitcoin-development at lists.sourceforge.net\n\u003e \u003e\u003e\u003e https://lists.sourceforge.net/lists/listinfo/bitcoin-development\n\u003e \u003e\u003e\u003e\n\u003e \u003e\u003e\u003e\n\u003e \u003e\u003e\n\u003e \u003e\n\u003e \u003e\n\u003e \u003e ------------------------------------------------------------------------------\n\u003e \u003e\n\u003e \u003e _______________________________________________\n\u003e \u003e Bitcoin-development mailing list\n\u003e \u003e Bitcoin-development at lists.sourceforge.net\n\u003e \u003e https://lists.sourceforge.net/lists/listinfo/bitcoin-development\n\u003e \u003e\n\u003e \u003e\n\u003e \n\u003e \n\u003e -- \n\u003e --\n\u003e Gavin Andresen\n\n\u003e ------------------------------------------------------------------------------\n\n\u003e _______________________________________________\n\u003e Bitcoin-development mailing list\n\u003e Bitcoin-development at lists.sourceforge.net\n\u003e https://lists.sourceforge.net/lists/listinfo/bitcoin-development\n\n\n-- \n----------------------------------------------------------------------------\nTroy Benjegerdes                 'da hozer'                  hozer at hozed.org\n7 elements      earth::water::air::fire::mind::spirit::soul        grid.coop\n\n      Never pick a fight with someone who buys ink by the barrel,\n         nor try buy a hacker who makes money by the megahash"}
