<oembed><type>rich</type><version>1.0</version><author_name>npub1ad7209g90jnu400x74quws0xv8gpxs2fxnjexnpwqnrxwa39exdq5gl2p6</author_name><author_url>https://nostr.ae/npub1ad7209g90jnu400x74quws0xv8gpxs2fxnjexnpwqnrxwa39exdq5gl2p6</author_url><provider_name>njump</provider_name><provider_url>https://nostr.ae</provider_url><html>📅 Original date posted:2011-12-18&#xA;🗒️ Summary of this message: The author expresses concern about the lack of an easy and secure solution for using aliases in Bitcoin transactions, and suggests using SSL communication authenticated with a bitcoin address as a potential solution.&#xA;📝 Original message:Pieter, it was more rhetorical question than asking for explanation, but&#xA;thanks anyway. As an Internet application developer, I of course understand&#xA;security issues while using HTTPS and CA.&#xA;&#xA;I have a gut feeling that there simply does not exist any single solution&#xA;which is both easy to use and secure enough. At least nobody mentioned it&#xA;yet. And if I need to choose between easy solution or secure solution for&#xA;aliases, I&#39;ll pick that easy one. I mean - we need some solution which will&#xA;be easy enough for daily use; it is something what we currently don&#39;t have.&#xA;But if I want to be really really sure I&#39;m using correct destination for&#xA;paying $1mil for a house, I can every time ask for real bitcoin addresses,&#xA;this is that secure way which we currently have.&#xA;&#xA;slush&#xA;&#xA;On Mon, Dec 19, 2011 at 2:14 AM, Pieter Wuille &lt;pieter.wuille at gmail.com&gt;wrote:&#xA;&#xA;&gt; On Mon, Dec 19, 2011 at 12:58:37AM +0100, slush wrote:&#xA;&gt; &gt; Maybe I&#39;m retarded, but where&#39;s the point in providing alliases&#xA;&gt; containing&#xA;&gt; &gt; yet another hash in URL?&#xA;&gt;&#xA;&gt; Any DNS-based alias system is vulnerable to spoofing. If I can make&#xA;&gt; people&#39;s&#xA;&gt; DNS server believe that mining.cz points to my IP, I&#39;ll receive payments&#xA;&gt; to&#xA;&gt; you...&#xA;&gt;&#xA;&gt; If no trusted CA is used to authenticate the communication, there is no way&#xA;&gt; to be sure the one you are asking how to pay, is the person you want to&#xA;&gt; pay.&#xA;&gt; Therefore, one solution is to put a bitcoin address in the identification&#xA;&gt; string itself, and requiring SSL communication authenticated using the&#xA;&gt; respective key.&#xA;&gt;&#xA;&gt; This makes the identification strings obviously less useful as aliases,&#xA;&gt; but pure aliases in the sense of human-typable strings have imho&#xA;&gt; limited usefulness anyway - in most cases these identification strings&#xA;&gt; will be communicated through other electronic means anyway.&#xA;&gt;&#xA;&gt; Furthermore, the embedded bitcoin address could be hidden from the user:&#xA;&gt; retrieved when first connecting, and stored together with the URI in&#xA;&gt; an address book. Like ssh, it could warn the user if the key changes&#xA;&gt; (which wil be ignored by most users anyway, but what do you do about&#xA;&gt; that?)&#xA;&gt;&#xA;&gt; --&#xA;&gt; Pieter&#xA;&gt;&#xA;&gt;&#xA;&gt; ------------------------------------------------------------------------------&#xA;&gt; Learn Windows Azure Live!  Tuesday, Dec 13, 2011&#xA;&gt; Microsoft is holding a special Learn Windows Azure training event for&#xA;&gt; developers. It will provide a great way to learn Windows Azure and what it&#xA;&gt; provides. You can attend the event by watching it streamed LIVE online.&#xA;&gt; Learn more at http://p.sf.net/sfu/ms-windowsazure&#xA;&gt; _______________________________________________&#xA;&gt; Bitcoin-development mailing list&#xA;&gt; Bitcoin-development at lists.sourceforge.net&#xA;&gt; https://lists.sourceforge.net/lists/listinfo/bitcoin-development&#xA;&gt;&#xA;-------------- next part --------------&#xA;An HTML attachment was scrubbed...&#xA;URL: &lt;http://lists.linuxfoundation.org/pipermail/bitcoin-dev/attachments/20111219/d492945b/attachment.html&gt;</html></oembed>