<oembed><type>rich</type><version>1.0</version><author_name>npub17ty4mumkv43w8wtt0xsz2jypck0gvw0j8xrcg6tpea25z2nh7meqf4qgyd</author_name><author_url>https://nostr.ae/npub17ty4mumkv43w8wtt0xsz2jypck0gvw0j8xrcg6tpea25z2nh7meqf4qgyd</author_url><provider_name>njump</provider_name><provider_url>https://nostr.ae</provider_url><html>📅 Original date posted:2015-02-05&#xA;📝 Original message:&gt;&#xA;&gt; Even if a user could get the BIP70 URL in the URI, they would still need&#xA;&gt; internet to access the URL.&#xA;&gt;&#xA;&#xA;The way Bitcoin Wallet does it, the bitcoin URI includes a MAC address&#xA;where you can download the request from. BIP70 does not depend on internet&#xA;access or HTTP, plus, you don&#39;t have to sign them.&#xA;&#xA;The name field might work but requires the merchant to set it, e.g. by&#xA;asking the payer what their name is, then typing it in, then the payer has&#xA;to wait for it to show up. By this point it&#39;s probably faster to have&#xA;scanned a QR code.&#xA;&#xA;Re: security. I&#39;ll repeat what I wrote up-thread in case you didn&#39;t see it:&#xA;&#xA;it&#39;s not clear to me at all that this partial address scheme is actually&#xA;&gt; secure. The assumption appears to be that the MITM must match the address&#xA;&gt; prefix generated by the genuine merchant. But if they can do a wireless&#xA;&gt; MITM they can just substitute their own address prefix/partial address, no?&#xA;&gt;&#xA;&gt; To avoid MITM attacks the sender must know who they are sending money to,&#xA;&gt; and that means they must see a human understandable name that&#39;s&#xA;&gt; cryptographically bound to the right public key. Displaying partial&#xA;&gt; addresses to the user is not going to solve this unless users manually&#xA;&gt; compare key prefixes across the screens.... which is even less convenient&#xA;&gt; than a QR code.&#xA;&gt;&#xA;-------------- next part --------------&#xA;An HTML attachment was scrubbed...&#xA;URL: &lt;http://lists.linuxfoundation.org/pipermail/bitcoin-dev/attachments/20150205/c3eb897f/attachment.html&gt;</html></oembed>