<oembed><type>rich</type><version>1.0</version><author_name>npub17ty4mumkv43w8wtt0xsz2jypck0gvw0j8xrcg6tpea25z2nh7meqf4qgyd</author_name><author_url>https://nostr.ae/npub17ty4mumkv43w8wtt0xsz2jypck0gvw0j8xrcg6tpea25z2nh7meqf4qgyd</author_url><provider_name>njump</provider_name><provider_url>https://nostr.ae</provider_url><html>📅 Original date posted:2012-11-26&#xA;📝 Original message:&gt; That&#39;s expected behaviour - except it&#39;s mainly be manipulated by *users*, not&#xA;&gt; viruses (which can just as easily manipulate whatever custom cert store we&#xA;&gt; use).&#xA;&#xA;The point of using signed invoices as virus protection isn&#39;t to change&#xA;what the user sees on the infected host. The point is the invoice can&#xA;be relayed to a second device that isn&#39;t also compromised which then&#xA;independently renders a payment confirmation screen (like your mobile&#xA;phone), and it has an identifier in it that&#39;s useful to people, like&#xA;bitmit.net instead of an address.&#xA;&#xA;If it was just showing you a Bitcoin address, that doesn&#39;t mean&#xA;anything to you so a virus on your PC could wait until you want to&#xA;make a large payment somewhere and swap out the address in use. You&#39;d&#xA;never know it was the wrong address and you&#39;d happily confirm on your&#xA;second device.&#xA;&#xA;For this to work, the seller has to be able to predict what certs you&#xA;have in all your devices. If it&#39;s up to the OS vendors then it&#39;s hard&#xA;to know and in practice all that&#39;ll happen is somebody will compile a&#xA;list of CAs that are &#34;known good&#34; (ie, present in all deployed mobile&#xA;and desktop OS&#39;) and that&#39;ll be the minimal cert list. No different to&#xA;if it was hard-coded in the spec.&#xA;&#xA;&gt; If I don&#39;t trust Joe&#39;s certs, I don&#39;t want Bitcoin overriding that no&#xA;&gt; matter who Joe is or what connections he has.&#xA;&#xA;Nothing says your wallet software can&#39;t provide cert management UI&#xA;like browsers do.&#xA;&#xA;In practice I have a feeling that cert management UI is one of the&#xA;least used parts of a browser. I&#39;ve used browsers for years and the&#xA;only time I&#39;ve ever had to go into those screens was to manage&#xA;installation/removal of self signed certs used by various&#xA;organizations. I never manually revoked a root authority. When it was&#xA;necessary due to breaches (Comodo/DigiNotar) the browser makers&#xA;revoked them for me.</html></oembed>