{"type":"rich","version":"1.0","author_name":"npub1798ncudyucap9jzzujjsgufx8tdykm8auzfledjcs6f6wf4ekqvq8lpmjt","author_url":"https://nostr.ae/npub1798ncudyucap9jzzujjsgufx8tdykm8auzfledjcs6f6wf4ekqvq8lpmjt","provider_name":"njump","provider_url":"https://nostr.ae","html":"📅 Original date posted:2015-02-10\n📝 Original message:BIP70 is a protocol for getting a user's wallet client communicate with a\nmerchant's server in order to agree on details like where to send the\npayment, how much to send, what the shipping address is, sending a receipt\nback, and much more using various extensions that adds more functionality.\n\nThere could even be advanced functionality for automatically negotiating\nterms. One example could be selecting a multisignature arbitrator both\nsides trust. Another could be to agree on the speed and type of delivery.\nMany more types of decisions could be automatically agreed upon.\n\nBut as it is now, it is designed to be initiated at the time of payment. If\nyou always want next-day delivery from online stores then you won't always\nknow if that's an option until you've filled the digital basket and gone\nthrough checkout. If you only want to shop with an arbitrator involved same\nthing applies.\n\nEverything that BIP70 enables happens at the last step only, as it is right\nnow.\n\nIf there could be a BIP70 HTML tag on web shops that automatically\ntriggered your wallet as soon as you visit the page, it would be possible\nfor a browser extension that talks to your wallet to tell you right away if\nthe web shop you're currently looking at has terms you consider acceptable\nor not (note: if your wallet client isn't installed on or linked to that\nsame machine, a visible Qr code would be an acceptable alternative which\nyou can scan in advance before you start shopping). This notification can\neven be automatically updated as you add and remove things from your cart\nand details like shipping options change.\n\nThis would massively simplify the shipping experience and make every web\nshop feel like Amazon.\n\nOf course this has privacy implications and increases exposure to potential\nwallet exploits, but the wallet can ask you if you intend to shop or not at\neach site before it even connects and send any information at all in order\nto mitigate both of those problems. This way it should be reasonably safe.\n\nAnother option would be to automatically connect but limit what data is\nsent in order to remain privacy preserving, until the user agrees to send\nprivate information.\n\nThis second method would also open up for the merchant to other send\nrelevant information such as details about various certifications from\nthird parties, which can include a certification that shows they have been\nbeen audited and approved by by entity X for purpose Y. If your wallet has\nthat entity whitelisted it will show you that certificate (for example\n\"Acme Audits have audited and approves of Merchant M's privacy policy and\ndata protection\"). With a list of predefined types of certifications that\nthe wallet understand and accepts, it could (by choice of the user) require\na certificate to be present to even allow you to make a purchase (lack of\nrequired certifications would result in automatic denial). No certificate =\nyour wallet never proceed to send private information.\n\nThoughts?\n\n- Sent from my tablet\n-------------- next part --------------\nAn HTML attachment was scrubbed...\nURL: \u003chttp://lists.linuxfoundation.org/pipermail/bitcoin-dev/attachments/20150210/db065fa8/attachment.html\u003e"}
