{"type":"rich","version":"1.0","author_name":"npub17ty4mumkv43w8wtt0xsz2jypck0gvw0j8xrcg6tpea25z2nh7meqf4qgyd","author_url":"https://nostr.ae/npub17ty4mumkv43w8wtt0xsz2jypck0gvw0j8xrcg6tpea25z2nh7meqf4qgyd","provider_name":"njump","provider_url":"https://nostr.ae","html":"📅 Original date posted:2015-02-05\n📝 Original message:\u003e\n\u003e Even if a user could get the BIP70 URL in the URI, they would still need\n\u003e internet to access the URL.\n\u003e\n\nThe way Bitcoin Wallet does it, the bitcoin URI includes a MAC address\nwhere you can download the request from. BIP70 does not depend on internet\naccess or HTTP, plus, you don't have to sign them.\n\nThe name field might work but requires the merchant to set it, e.g. by\nasking the payer what their name is, then typing it in, then the payer has\nto wait for it to show up. By this point it's probably faster to have\nscanned a QR code.\n\nRe: security. I'll repeat what I wrote up-thread in case you didn't see it:\n\nit's not clear to me at all that this partial address scheme is actually\n\u003e secure. The assumption appears to be that the MITM must match the address\n\u003e prefix generated by the genuine merchant. But if they can do a wireless\n\u003e MITM they can just substitute their own address prefix/partial address, no?\n\u003e\n\u003e To avoid MITM attacks the sender must know who they are sending money to,\n\u003e and that means they must see a human understandable name that's\n\u003e cryptographically bound to the right public key. Displaying partial\n\u003e addresses to the user is not going to solve this unless users manually\n\u003e compare key prefixes across the screens.... which is even less convenient\n\u003e than a QR code.\n\u003e\n-------------- next part --------------\nAn HTML attachment was scrubbed...\nURL: \u003chttp://lists.linuxfoundation.org/pipermail/bitcoin-dev/attachments/20150205/c3eb897f/attachment.html\u003e"}
