{"type":"rich","version":"1.0","author_name":"npub1xg2m84malu0cfm4444r0kysx4rgk27e75aj6sz6538kw8fcz627qeadsv7","author_url":"https://nostr.ae/npub1xg2m84malu0cfm4444r0kysx4rgk27e75aj6sz6538kw8fcz627qeadsv7","provider_name":"njump","provider_url":"https://nostr.ae","html":"📅 Original date posted:2015-02-22\n📝 Original message:On 02/23/2015 12:32 AM, Andy Schroder wrote:\n\u003e I guess we need to decide whether we want to consider NFC communication\n\u003e private or not. I don't know that I think it can be. An eavesdropper can\n\u003e place a tiny snooping device near and read the communication. If it is\n\u003e just passive, then the merchant/operator won't realize it's there. So, I\n\u003e don't know if I like your idea (mentioned in your other reply) of\n\u003e putting the session key in the URL is a good idea?\n\nI think the \"trust by proximity\" is the best we've got. If we don't\ntrust the NFC link (or the QR code scan), what other options have we\ngot? Speaking the session key by voice? Bad UX, and can be eavesdropped\nas well of course."}
