<oembed><type>rich</type><version>1.0</version><author_name>npub17ty4mumkv43w8wtt0xsz2jypck0gvw0j8xrcg6tpea25z2nh7meqf4qgyd</author_name><author_url>https://nostr.ae/npub17ty4mumkv43w8wtt0xsz2jypck0gvw0j8xrcg6tpea25z2nh7meqf4qgyd</author_url><provider_name>njump</provider_name><provider_url>https://nostr.ae</provider_url><html>📅 Original date posted:2012-11-27&#xA;📝 Original message:&gt; Personally, I&#39;d like to see fewer implicit ties to X509.  With X509 as one&#xA;&gt; option.&#xA;&#xA;That&#39;s pretty much what we have today - in future other schemes can be&#xA;proposed as extensions. Protocol buffers are easily extended, they&#xA;ignore unknown fields. Then you&#39;d wait and see what the invoice&#xA;request looked like and produce an invoice with the right security&#xA;bits.&#xA;&#xA;&gt; In particular two additional identification types:&#xA;&gt;&#xA;&gt;  - GnuPG (obviously)&#xA;&#xA;It&#39;s not obvious to me, incidentally. The web of trust has been&#xA;dead-on-arrival since it was first proposed, and for good reasons.&#xA;SSL/X.509, for better or worse, has significant usage.&#xA;&#xA;Your case of a small business is a perfect example of people who won&#39;t&#xA;be using GPG. If they don&#39;t want to buy an SSL cert, they can just as&#xA;well put a reference number in the memo field or a &#34;Hey Bob, here is&#xA;the bill we discussed&#34;. The payer does not get the multi-factor auth&#xA;protection so if their computer has a virus, they may be hosed. But&#xA;that&#39;s good incentive for sellers to get verified. Some CA authorities&#xA;do it for free these days.</html></oembed>