{"type":"rich","version":"1.0","author_name":"npub1dtr22xd42nv07un2xq0rmtkqkjylgsmexau0anxxafa9xmmn2ncshu7wrs","author_url":"https://nostr.ae/npub1dtr22xd42nv07un2xq0rmtkqkjylgsmexau0anxxafa9xmmn2ncshu7wrs","provider_name":"njump","provider_url":"https://nostr.ae","html":"📅 Original date posted:2012-11-26\n📝 Original message:On Monday, November 26, 2012 11:16:03 PM Mike Hearn wrote:\n\u003e They could be included as well of course, but from a seller\n\u003e perspective the most important thing is consistency. You have to be\n\u003e able to predict what CAs the user has, otherwise your invoice would\n\u003e appear in the UI as unverified and is subject to manipulation by\n\u003e viruses, etc.\n\nThat's expected behaviour - except it's mainly be manipulated by *users*, not \nviruses (which can just as easily manipulate whatever custom cert store we \nuse). If I don't trust Joe's certs, I don't want Bitcoin overriding that no \nmatter who Joe is or what connections he has.\n\n\u003e So using the OS cert store would effectively restrict merchants to the\n\u003e intersection of what ships in all the operating systems their users\n\u003e use, which could be unnecessarily restrictive. As far as I know, every\n\u003e browser has its own cert store for that reason.\n\nBrowsers with this bug are not relevant IMO."}
