<oembed><type>rich</type><version>1.0</version><author_name>npub1xz8q68hmzur6c6uje593nscy3q4njx05h4vnxmz2wxxptx7u7casl2925u</author_name><author_url>https://nostr.ae/npub1xz8q68hmzur6c6uje593nscy3q4njx05h4vnxmz2wxxptx7u7casl2925u</author_url><provider_name>njump</provider_name><provider_url>https://nostr.ae</provider_url><html>📅 Original date posted:2011-12-16&#xA;🗒️ Summary of this message: Various proposals for linking Bitcoin addresses to domain names or aliases have limitations, including centralization, reliance on HTTPS and CA, and DNSSEC requirements. Namecoin is a potential solution.&#xA;📝 Original message:On Fri, Dec 16, 2011 at 1:52 PM, Khalahan &lt;khal at dot-bit.org&gt; wrote:&#xA;&gt; The number of proposals is not infinite, here are their problems :&#xA;&gt;&#xA;&gt; - FirstBits : centralized&#xA;&gt; - DNS TXT Records : DNSSEC is required to have a minimum of security, limits&#xA;&gt; usage to engineers, limits usage to some domain names (i won&#39;t be able to&#xA;&gt; use a gmail address for example, because i don&#39;t control the gmail.com&#xA;&gt; domain)&#xA;&#xA;The same goes for http(s) one would not be able to use&#xA;http://google.com/user unless google offers the services.&#xA;&#xA;ALSO look at DANE for getting around the certificate requirement for https&#xA;&#xA;&gt; - Server Service (DNS + a daemon) : Same as DNS TXT records&#xA;&#xA;DNS TXT are not the only way forward, also registry/registrars can facilitate.&#xA;&#xA;&gt; - HTTPS Web service : relies on HTTPS and CA, bitcoin needs to be able to&#xA;&gt; check the full certificate chain and access a list of up-to-date certificate&#xA;&gt; authorities (installed on the OS or provided with bitcoin). And don&#39;t forget&#xA;&gt; the CA model is not 100% reliable (several CA hacked this year + possible&#xA;&gt; government control...).&#xA;&#xA;This most likely relies on a paid, valid certificate (that expires),&#xA;no self signed certs. I admit that running a secured https server with&#xA;a valid CA signed  cet is as simple/hard as running a DNSSEC authority&#xA;zone.&#xA;&#xA;using a x.509 certificate to secure a bitcoin transaction removes some&#xA;of the anonymity of the transaction by allowing the lookup to identify&#xA;the certification, ca, crl etc thus connecting a transaction/bitcoin&#xA;address to the cert and to its issuing authority. No matter the&#xA;frequency of the destination bitcoin address changing.&#xA;&#xA;IMNSHO, leveraging CAs to secure http to provide a lookup translation&#xA;to a bitcoin address will only erode anonymity. While DNS is connected&#xA;to whois there are provision for hiding behind a proxy where to the&#xA;best of my knowledge there are no such provisions offered by CA&#39;s&#xA;issuing x.509 certificates.&#xA;&#xA;Should self signed cers be &#34;allowed&#34; or encouraged only decreases&#xA;security. Clearly DANE would be the only way to mitigate this&#xA;situation but then you are back to relying on DNSSEC to bind the x.509&#xA;cert.&#xA;&#xA;wash, rinse,  ...&#xA;&#xA;-rick&#xA;&#xA;&gt; - IP Transactions : This proposal seeks to enable DNS lookups for IP&#xA;&gt; transactions =&gt; same as above&#xA;&gt;&#xA;&gt; I know that providing a namecoin daemon with bitcoin is not the lighter&#xA;&gt; solution, but, if a better one existed i guess it would have already been&#xA;&gt; integrated into bitcoin... (see in what state is my first attempt with the&#xA;&gt; HTTPS proposal : Send payments to emails, urls and domains in GUI - khalahan&#xA;&gt; opened this pull request April 20, 2011)&#xA;&gt;&#xA;&gt; So, what&#39;s next ?&#xA;&gt;&#xA;&gt; Le 16/12/2011 20:54, slush a écrit :&#xA;&gt;&#xA;&gt; Khalahan, honestly, using namecoin for aliases is (for me) clean example of&#xA;&gt; over-engineering. I mean - it will definitely work if implemented properly.&#xA;&gt; I played with a namecoin a bit (as my pool was the first &#39;big&#39; pool&#xA;&gt; supporting merged mining), but I think there&#39;s really long way to provide&#xA;&gt; such alias system in namecoin and *cleanly integrate it with bitcoin*. Don&#39;t&#xA;&gt; forget that people who want to do lookup need to maintain also namecoin&#xA;&gt; blockchain with their bitcoin client. It goes against my instinct of keeping&#xA;&gt; stuff easy.&#xA;&gt;&#xA;&gt; For example, yesterday I implemented HTTPS lookup for addresses into my fork&#xA;&gt; of Electrum client. I did it in 15 minutes, it works as expected, it does&#xA;&gt; the job and the implementation is really transparent, becuase implementation&#xA;&gt; is 20 lines of code. There&#39;s no magic transformation, no forced &#34;?handle=&#34;&#xA;&gt; parameters or whatever. And I don&#39;t care if somebody provide URL&#xA;&gt; https://some.strange.domain/name-of-my-dog?myhandle=5678iop&amp;anything_else=True&#xA;&gt;&#xA;&gt; And everybody can do the same in their clients, in their merchant solutions,&#xA;&gt; websites or whatever. Everybody can do HTTPS lookup. But try to explain DNS,&#xA;&gt; Namecoin, IIBAN, email aliases to other programmers...&#xA;&gt;&#xA;&gt; Those IIBAN - well, why not. At least I see the potential in PR. So far I&#xA;&gt; understand it as some teoretic concept which is not supported by anything&#xA;&gt; else right now. Give it few years until it matures and then add IIBAN alias&#xA;&gt; to Bitcoin client too.&#xA;&gt;&#xA;&gt; Maybe I&#39;m repeating myself already, but the way to go is to make aliases as&#xA;&gt; easy as possible, so everybody can implement it in their own solution and&#xA;&gt; thus practially remove the need of using standard bitcoin addresses for&#xA;&gt; normal users. Using some superior technology, which is hard to implement or&#xA;&gt; even understand won&#39;t solve the situation, because it will ends up with some&#xA;&gt; reference implementation in standard client only and nobody else will use&#xA;&gt; it.&#xA;&gt;&#xA;&gt; slush&#xA;&gt;&#xA;&gt;&#xA;&gt; --&#xA;&gt; Best Regards,&#xA;&gt; Khalahan&#xA;&gt; http://dot-bit.org/&#xA;&gt;&#xA;&gt;&#xA;&gt; ------------------------------------------------------------------------------&#xA;&gt; Learn Windows Azure Live!  Tuesday, Dec 13, 2011&#xA;&gt; Microsoft is holding a special Learn Windows Azure training event for&#xA;&gt; developers. It will provide a great way to learn Windows Azure and what it&#xA;&gt; provides. You can attend the event by watching it streamed LIVE online.&#xA;&gt; Learn more at http://p.sf.net/sfu/ms-windowsazure&#xA;&gt; _______________________________________________&#xA;&gt; Bitcoin-development mailing list&#xA;&gt; Bitcoin-development at lists.sourceforge.net&#xA;&gt; https://lists.sourceforge.net/lists/listinfo/bitcoin-development&#xA;&gt;</html></oembed>