{"type":"rich","version":"1.0","author_name":"npub1azvhdrf9fu6n0tm7yez4j6zcxcedp2ct6nrcq3z74naqs7kgpk8s5t2krq","author_url":"https://nostr.ae/npub1azvhdrf9fu6n0tm7yez4j6zcxcedp2ct6nrcq3z74naqs7kgpk8s5t2krq","provider_name":"njump","provider_url":"https://nostr.ae","html":"📅 Original date posted:2015-06-21\n📝 Original message:\u003e On Jun 20, 2015, at 11:45 PM, Jeff Garzik \u003cjgarzik at bitpay.com\u003e wrote:\n\u003e \n\u003e On Sat, Jun 20, 2015 at 5:54 PM, Eric Lombrozo \u003celombrozo at gmail.com \u003cmailto:elombrozo at gmail.com\u003e\u003e wrote:\n\u003e  but we NEED to be applying some kind of pressure on the merchant end to upgrade their stuff to be more resilient\n\u003e \n\u003e Can you be specific?  What precise technical steps would you have BitPay and Coinbase do?  We upgrade our stuff to... what exactly?\n\u003e \n\u003e --\n\u003e Jeff Garzik\n\u003e Bitcoin core developer and open source evangelist\n\u003e BitPay, Inc.      https://bitpay.com/ \u003chttps://bitpay.com/\u003e\nThanks for asking *the* question, Jeff. We often get caught up in these philosophical debates…but at the end of the day we need something concrete.\n\nEven more important than the specific software you’re using is the security policy.\n\nIf you must accept zero confirmation transactions, there are a few concrete things you can do to reduce your exposure:\n\n1) limit the transaction amounts for zero confirmation transactions - do not accept them for very high priced goods…especially if they require physical shipping.\n2) limit the total amount of unconfirmed revenue you’ll tolerate at any given moment - if the amount is exceeded, require confirmations.\n3) give merchants of subscription services (i.e. servers, hosting, etc…) the ability to shut the user out if a double-spend is detected.\n4) collect legal information on purchasers (or have the merchants collect this information) so you have someone to go after if they try to screw you\n5) create a risk profile for users…and flag suspicious behavior (i.e. someone trying to purchase a bunch of stuff that totally doesn’t fit into their purchasing habits).\n6) get insurance (although right now reasonably-priced insurance is probably pretty hard to obtain since statistics are generally of little use…we’re entering uncharted territory).\n7) set up a warning system and a “panic” button so that if you start to see an attack you can immediately disable all zero confirmation transactions system-wide.\n8) independently verify all inbound transactions and connect to multiple network nodes…check them against one another.\n\n\nAs for software tools to accomplish these things, we can talk about that offline :)\n\n\n- Eric Lombrozo\n\n\n\n\n-------------- next part --------------\nAn HTML attachment was scrubbed...\nURL: \u003chttp://lists.linuxfoundation.org/pipermail/bitcoin-dev/attachments/20150621/95ab06d4/attachment.html\u003e\n-------------- next part --------------\nA non-text attachment was scrubbed...\nName: signature.asc\nType: application/pgp-signature\nSize: 842 bytes\nDesc: Message signed with OpenPGP using GPGMail\nURL: \u003chttp://lists.linuxfoundation.org/pipermail/bitcoin-dev/attachments/20150621/95ab06d4/attachment.sig\u003e"}
