<oembed><type>rich</type><version>1.0</version><author_name>npub1pa6l5jatv92d4vzk566r58zjawpuu0we8nhrywfhp90f9948e0tsx3rxtp</author_name><author_url>https://nostr.ae/npub1pa6l5jatv92d4vzk566r58zjawpuu0we8nhrywfhp90f9948e0tsx3rxtp</author_url><provider_name>njump</provider_name><provider_url>https://nostr.ae</provider_url><html>📅 Original date posted:2014-04-04&#xA;📝 Original message:&gt;&#xA;&gt; The goal of writing a BIP seems to be to get lots of different wallet&#xA;&gt; authors to write lots of code for you - but I *am* a wallet author, and I&#xA;&gt; don&#39;t think that&#39;s the right way to get traction with a new scheme.&#xA;&gt;&#xA;&#xA;I started without a BIP and the feedback I got is that I should to a BIP.&#xA;We cannot write all the code for all the wallets ; this is after all a&#xA;communauty project.&#xA;However we have and we will propose bounties for each wallet to support&#xA;natively the protocol.&#xA;&#xA;&#xA;&gt; For instance the TREZOR guys would have to support your new protocol&#xA;&gt; otherwise if I paid my hotel bill with my TREZOR I couldn&#39;t open the door&#xA;&gt; when I got there! But they probably have better things to be doing right&#xA;&gt; now.&#xA;&gt;&#xA;&#xA;Yes you are right. But if the concept of authenticating yourself gets&#xA;traction, they will probably do it.&#xA;&#xA;&#xA;&gt; The key difference between just generating a client certificate and using&#xA;&gt; a Bitcoin address is that the client certificate is something that is used&#xA;&gt; *specifically* for identification. It leaves no trace in the block chain,&#xA;&gt; so no weird privacy issues, it doesn&#39;t matter how you manage your wallet,&#xA;&gt; and you don&#39;t have to persuade lots of people to support your idea because&#xA;&gt; it was already done &gt;10 years ago and basically every browser/web server&#xA;&gt; supports it.&#xA;&gt;&#xA;&#xA;My view on this is mainly about the UX and the fact everyone in Bitcoinland&#xA;has a wallet.&#xA;It&#39;s a approach leveraging this fact, with the possibility to build&#xA;interesting apps combining address auth and the blockchain.&#xA;&#xA;I understand the problems related to multisig, contracts etc,&#xA;There is no such thing as a from address in a transaction, however many&#xA;services still take first tx as the return address.&#xA;People will always find way of building and doing stuff (cf the message in&#xA;the blockchain debate).&#xA;&#xA;&#xA;&gt; Some reasons client certs aren&#39;t more widely used boil down to:&#xA;&gt;&#xA;&gt;    1. People like passwords. In particular they like forgetting them and&#xA;&gt;    then having friendly people assist them to get it back. Client certs can&#xA;&gt;    support this use case, but only if apps are checking the identity in them&#xA;&gt;    and not the key.&#xA;&gt;    2. The UI for managing client certs in browsers is pretty horrible.&#xA;&gt;    There&#39;s little incentive to improve it because of (1).&#xA;&gt;    3. Cross-device sync doesn&#39;t work very well. Apple are starting to&#xA;&gt;    tackle this with their iCloud Keychain Sync service but then of course,&#xA;&gt;    Apple has all your keys and you may well just sign in to things with your&#xA;&gt;    Apple account (if it were to be supported). Cross-device sync where the&#xA;&gt;    server *doesn&#39;t* get your keys is supported by Chrome for passwords,&#xA;&gt;    but not client certs, because (1)&#xA;&gt;&#xA;&gt; None of the above issues have any obvious fix lurking within Bitcoin.&#xA;&gt;&#xA;&#xA;There is also the benefit of revocation with certificate and central&#xA;authority.&#xA;&#xA;But, again, you already have a wallet and a Bitcoin address.&#xA;So if you add a simple auth protocol, people will use it at no cost.&#xA;&#xA;Eric&#xA;-------------- next part --------------&#xA;An HTML attachment was scrubbed...&#xA;URL: &lt;http://lists.linuxfoundation.org/pipermail/bitcoin-dev/attachments/20140404/9e6d4ffc/attachment.html&gt;</html></oembed>