<oembed><type>rich</type><version>1.0</version><author_name>npub1kf0ppcjaguxekg24yx6smgxlu73qn0k8lm0t2wrqc0scpl7u3sgsmf3f58</author_name><author_url>https://nostr.ae/npub1kf0ppcjaguxekg24yx6smgxlu73qn0k8lm0t2wrqc0scpl7u3sgsmf3f58</author_url><provider_name>njump</provider_name><provider_url>https://nostr.ae</provider_url><html>📅 Original date posted:2014-09-12&#xA;📝 Original message:Indeed -- Every byte added to the QR code makes it more difficult to&#xA;be used in restaurants, pubs and other low-light conditions.  BitPay&#xA;tested some of these scenarios.&#xA;&#xA;Scannability is absolutely impacted.&#xA;&#xA;On Fri, Sep 12, 2014 at 9:49 AM, Mike Hearn &lt;mike at plan99.net&gt; wrote:&#xA;&gt; A few thoughts on this:&#xA;&gt;&#xA;&gt; (1) Base64 of SHA256 seems overkill. 256 bits of hash is a lot. The risk&#xA;&gt; here is that a MITM intercepts the payment request, which will be typically&#xA;&gt; requested just seconds after the QR code is vended. 80 bits of entropy would&#xA;&gt; still be a lot and take a long time to brute force, whilst keeping QR codes&#xA;&gt; more compact, which impacts scannability.&#xA;&gt;&#xA;&gt; (2) This should not be necessary in the common HTTPS context. The QR code&#xA;&gt; itself is going to be fetched from some service, over HTTPS. I see no&#xA;&gt; reasonable attacker that can MITM the request for the BIP70 message but not&#xA;&gt; the request to get the QR code. Adding a hash makes QR codes more bloated&#xA;&gt; and harder to scan, all on the assumption that HTTPS is broken in some odd&#xA;&gt; way that we haven&#39;t actually ever seen in practice.&#xA;&gt;&#xA;&gt; (3) This can be useful in the Bluetooth context, but then again, we could&#xA;&gt; also do things a different way by signing with the key in the first part of&#xA;&gt; the URI, thus avoiding the need for a hash.&#xA;&gt;&#xA;&gt; I know I&#39;ve been around the loop on this one with Andreas many times. But&#xA;&gt; this BIP doesn&#39;t fix any actually existing problem in the previous spec. It&#xA;&gt; exists because Andreas thinks SSL is useless. If SSL is useless we all have&#xA;&gt; much bigger problems.&#xA;&gt;&#xA;&gt; ------------------------------------------------------------------------------&#xA;&gt; Want excitement?&#xA;&gt; Manually upgrade your production database.&#xA;&gt; When you want reliability, choose Perforce&#xA;&gt; Perforce version control. Predictably reliable.&#xA;&gt; http://pubads.g.doubleclick.net/gampad/clk?id=157508191&amp;iu=/4140/ostg.clktrk&#xA;&gt; _______________________________________________&#xA;&gt; Bitcoin-development mailing list&#xA;&gt; Bitcoin-development at lists.sourceforge.net&#xA;&gt; https://lists.sourceforge.net/lists/listinfo/bitcoin-development&#xA;&gt;&#xA;&#xA;&#xA;&#xA;-- &#xA;Jeff Garzik&#xA;Bitcoin core developer and open source evangelist&#xA;BitPay, Inc.      https://bitpay.com/</html></oembed>