<oembed><type>rich</type><version>1.0</version><author_name>npub1xg2m84malu0cfm4444r0kysx4rgk27e75aj6sz6538kw8fcz627qeadsv7</author_name><author_url>https://nostr.ae/npub1xg2m84malu0cfm4444r0kysx4rgk27e75aj6sz6538kw8fcz627qeadsv7</author_url><provider_name>njump</provider_name><provider_url>https://nostr.ae</provider_url><html>📅 Original date posted:2015-02-22&#xA;📝 Original message:On 02/23/2015 12:32 AM, Andy Schroder wrote:&#xA;&gt; I guess we need to decide whether we want to consider NFC communication&#xA;&gt; private or not. I don&#39;t know that I think it can be. An eavesdropper can&#xA;&gt; place a tiny snooping device near and read the communication. If it is&#xA;&gt; just passive, then the merchant/operator won&#39;t realize it&#39;s there. So, I&#xA;&gt; don&#39;t know if I like your idea (mentioned in your other reply) of&#xA;&gt; putting the session key in the URL is a good idea?&#xA;&#xA;I think the &#34;trust by proximity&#34; is the best we&#39;ve got. If we don&#39;t&#xA;trust the NFC link (or the QR code scan), what other options have we&#xA;got? Speaking the session key by voice? Bad UX, and can be eavesdropped&#xA;as well of course.</html></oembed>