<oembed><type>rich</type><version>1.0</version><author_name>npub17ty4mumkv43w8wtt0xsz2jypck0gvw0j8xrcg6tpea25z2nh7meqf4qgyd</author_name><author_url>https://nostr.ae/npub17ty4mumkv43w8wtt0xsz2jypck0gvw0j8xrcg6tpea25z2nh7meqf4qgyd</author_url><provider_name>njump</provider_name><provider_url>https://nostr.ae</provider_url><html>📅 Original date posted:2014-04-04&#xA;📝 Original message:On Fri, Apr 4, 2014 at 3:22 PM, Eric Larchevêque &lt;elarch at gmail.com&gt; wrote:&#xA;&#xA;&gt; I see only benefits for the entire ecosystem, and if I&#39;m working on such a&#xA;&gt; proposition it is because I really need this feature.&#xA;&gt;&#xA;&#xA;Why do you need it? Because you don&#39;t want to implement a login system?&#xA;Very, very few websites are the sort of place where they&#39;d want to&#xA;authenticate with only a Bitcoin address. If for no other reason than&#xA;they&#39;d have no way to email you, and if you lost your wallet, you&#39;d lose&#xA;all your associated data.&#xA;&#xA;&#xA;&gt; Without such a standard protocol, you could never envision a pure Bitcoin&#xA;&gt; physical locker rental, or booking an hotel room via Bitcoin and opening&#xA;&gt; the door through the paying address.&#xA;&gt;&#xA;&#xA;In future there often won&#39;t be a simple paying address. For instance, if my&#xA;coins are in a multi-sig relationship with a risk analysis service, there&#xA;will be two keys for each input and an arbitrary number of inputs. So does&#xA;that mean the risk analysis service gets to open my locker? Why?&#xA;&#xA;What if I do a shared spend/CoinJoin type tx? Now anyone who took part in&#xA;the shared tx with me can get into my hotel room too?&#xA;&#xA;These are the kinds of problems that crop up when you mix together two&#xA;different things: the act of paying, and the act of identifying yourself.&#xA;You&#39;re assuming that replacing a password people can remember with a&#xA;physical token (their phone) which can be stolen or lost, would be seen as&#xA;an upgrade. Given a choice between two physical lockers, one of which lets&#xA;me open it with a password and one of which insists on a cryptographic&#xA;token, I&#39;m going to go for the former because the chances of me losing my&#xA;phone is much higher than me forgetting my password.&#xA;&#xA;All the tools you need already exist in the form of client certificates,&#xA;with the advantage that web servers and web browsers already support them.&#xA;The biggest pain point with them is backup and cross-device sync, which of&#xA;course wallets suffer from too!&#xA;-------------- next part --------------&#xA;An HTML attachment was scrubbed...&#xA;URL: &lt;http://lists.linuxfoundation.org/pipermail/bitcoin-dev/attachments/20140404/3477a62d/attachment.html&gt;</html></oembed>