<oembed><type>rich</type><version>1.0</version><author_name>npub1tjephawh7fdf6358jufuh5eyxwauzrjqa7qn50pglee4tayc2ntqcjtl6r</author_name><author_url>https://nostr.ae/npub1tjephawh7fdf6358jufuh5eyxwauzrjqa7qn50pglee4tayc2ntqcjtl6r</author_url><provider_name>njump</provider_name><provider_url>https://nostr.ae</provider_url><html>📅 Original date posted:2011-12-18&#xA;🗒️ Summary of this message: Using DNS-based alias systems for Bitcoin payments is vulnerable to spoofing. One solution is to embed a Bitcoin address in the identification string itself.&#xA;📝 Original message:On Mon, Dec 19, 2011 at 12:58:37AM +0100, slush wrote:&#xA;&gt; Maybe I&#39;m retarded, but where&#39;s the point in providing alliases containing&#xA;&gt; yet another hash in URL?&#xA;&#xA;Any DNS-based alias system is vulnerable to spoofing. If I can make people&#39;s&#xA;DNS server believe that mining.cz points to my IP, I&#39;ll receive payments to&#xA;you...&#xA;&#xA;If no trusted CA is used to authenticate the communication, there is no way&#xA;to be sure the one you are asking how to pay, is the person you want to pay.&#xA;Therefore, one solution is to put a bitcoin address in the identification&#xA;string itself, and requiring SSL communication authenticated using the&#xA;respective key.&#xA;&#xA;This makes the identification strings obviously less useful as aliases,&#xA;but pure aliases in the sense of human-typable strings have imho&#xA;limited usefulness anyway - in most cases these identification strings&#xA;will be communicated through other electronic means anyway.&#xA;&#xA;Furthermore, the embedded bitcoin address could be hidden from the user:&#xA;retrieved when first connecting, and stored together with the URI in&#xA;an address book. Like ssh, it could warn the user if the key changes&#xA;(which wil be ignored by most users anyway, but what do you do about&#xA;that?)&#xA;&#xA;-- &#xA;Pieter</html></oembed>