{"type":"rich","version":"1.0","author_name":"npub1798ncudyucap9jzzujjsgufx8tdykm8auzfledjcs6f6wf4ekqvq8lpmjt","author_url":"https://nostr.ae/npub1798ncudyucap9jzzujjsgufx8tdykm8auzfledjcs6f6wf4ekqvq8lpmjt","provider_name":"njump","provider_url":"https://nostr.ae","html":"📅 Original date posted:2015-02-23\n📝 Original message:Den 23 feb 2015 08:38 skrev \"Andy Schroder\" \u003cinfo at andyschroder.com\u003e:\n\u003e\n\u003e I agree that NFC is the best we have as far as a trust anchor that you\nare paying the right person. The thing I am worried about is the privacy\nloss that could happen if there is someone passively monitoring the\nconnection. So, in response to some of your comments below and also in\nresponse to some of Eric Voskuil's comments in another recent e-mail:\n\n\u003eFrom the sources I can find NFC don't provide full privacy, but some\nmodulations are MITM resistant to varying degrees, some aren't at all, and\nthey are all susceptible to denial of service via jammers.\n\nIf the merchant system monitors the signal strength and similar metrics, a\nMITM that alters data (or attempts to) should be detectable, allowing it to\nshut down the connection.\n\nUsing NFC for key exchange to establish an encrypted link should IMHO be\nsecure enough.\n\nhttp://resources.infosecinstitute.com/near-field-communication-nfc-technology-vulnerabilities-and-principal-attack-schema/\n-------------- next part --------------\nAn HTML attachment was scrubbed...\nURL: \u003chttp://lists.linuxfoundation.org/pipermail/bitcoin-dev/attachments/20150223/4bea3a57/attachment.html\u003e"}
