{"type":"rich","version":"1.0","author_name":"npub1sgs97fe0n9wehe6zw7drcxdz4cy9yt9pfqjv8gasz5jlk4zezc0quppx3c","author_url":"https://nostr.ae/npub1sgs97fe0n9wehe6zw7drcxdz4cy9yt9pfqjv8gasz5jlk4zezc0quppx3c","provider_name":"njump","provider_url":"https://nostr.ae","html":"📅 Original date posted:2015-02-05\n📝 Original message:On 02/05/2015 12:28 PM, Mike Hearn wrote:\n\u003e The donation to live performer example is good - there's no issue of\n\u003e accidentally paying for someone else in this context as there's only one\n\u003e recipient, but many senders.\n\nI'm not sure you could assume this, even if the payer only received one\nbroadcast. And if the payer receives multiple, it constitutes a DOS on\nthe scenario, potentially unintentional.\n\n\u003e The issue of confused payments remains in other situations though.\n\nAgree, the problem of the payer strongly identifying the receiver\nrequires either proximity (NFC or QR code scan from the known-good\nsource) or PKI/WoT. The problem can't be resolved through a broadcast.\n\n\u003e For the coffee shop use case, it'd be nicer (I think) if we aim for a\n\u003e Square-style UI where the device broadcasts a (link to) a photo of the\n\u003e user combined with a bluetooth MAC. Then the merchant tablet can show\n\u003e faces of people in the shop, and can push a payment request to the users\n\u003e device. That device can then buzz the user, show a confirmation screen,\n\u003e put something on their smart watch etc or just auto-authorise the\n\u003e payment because the BIP70 signature is from a trusted merchant. User\n\u003e never even needs to touch their phone at all.\n\nI'm imagining myself walking around broadcasting my photo and MAC\naddress while hucksters push payment requests to me for approval, while\nrecording my photo and correlating it to my address. It will pretty\nquickly turn in to a scenario where I need to touch something before\nthis is turned on.\n\n\u003e On Thu, Feb 5, 2015 at 9:06 PM, Paul Puey \u003cpaul at airbitz.co\n\u003e \u003cmailto:paul at airbitz.co\u003e\u003e wrote:\n\u003e \n\u003e     The BIP70 protocol would preclude individuals from utilizing the P2P\n\u003e     transfer spec. It would also require that a Sender have internet\n\u003e     connectivity to get the payment protocol info. BLE could enable\n\u003e     payment w/o internet by first transferring the URI to from Recipient\n\u003e     to Sender. Then in the future, we could sign a Tx and send it over\n\u003e     BLE back to the recipient (who would still need internet to verify\n\u003e     the Tx). This is an important use case for areas with poor 3G/4G\n\u003e     connectivity as I've experience myself.\n\u003e \n\u003e     Also, due to Android issues, NFC is incredibly clunky. The URI\n\u003e     Sender is required to tap the screen *while* the two phones are in\n\u003e     contact. We support NFC the same way Bitcoin Wallet does, but unless\n\u003e     the payment recipient has a custom Android device (which a merchant\n\u003e     might) then the usage model is worse than scanning a QR code. BLE\n\u003e     also allows people to pay at a distance such as for a donation to a\n\u003e     live performer. We'll look at adding this to the Motivation section.\n\u003e \n\u003e     From: Andreas Schildbach \u003candreas at sc...\u003e - 2015-02-05 13:47:04\n\u003e \n\u003e     Thanks Paul, for writing up your protocol!\n\u003e \n\u003e     First thoughts:\n\u003e \n\u003e     For a BIP standard, I think we should skip \"bitcoin:\" URIs entirely and\n\u003e     publish BIP70 payment requests instead. URIs mainly stick around because\n\u003e     of QR codes limited capacity. BIP70 would partly address the \"copycat\"\n\u003e     problem by signing payment requests.\n\u003e \n\u003e     In your Motivation section, I miss some words about NFC. NFC already\n\u003e     addresses all of the usability issues mentioned and is supported by\n\u003e     mobile wallets since 2011. That doesn't mean your method doesn't make\n\u003e     sense in some situations, but I think it should be explained why to\n\u003e     prefer broadcasting payment requests over picking them up via near field\n\u003e     radio.\n\n\n-------------- next part --------------\nA non-text attachment was scrubbed...\nName: signature.asc\nType: application/pgp-signature\nSize: 473 bytes\nDesc: OpenPGP digital signature\nURL: \u003chttp://lists.linuxfoundation.org/pipermail/bitcoin-dev/attachments/20150205/829bd26c/attachment.sig\u003e"}
