<oembed><type>rich</type><version>1.0</version><author_name>npub10r66s2stvnancx9axwnfc5a34asjkwkgmkq7ztm5hf30x7fa4szsv9afdw</author_name><author_url>https://nostr.ae/npub10r66s2stvnancx9axwnfc5a34asjkwkgmkq7ztm5hf30x7fa4szsv9afdw</author_url><provider_name>njump</provider_name><provider_url>https://nostr.ae</provider_url><html>📅 Original date posted:2018-11-08&#xA;📝 Original message:&gt; Copying addresses to the clipboard should be discouraged, rather than&#xA;&gt; supported.&#xA;&#xA;Do you know any reasonably convenient mechanism for end user to&#xA;transfer an address from, say, a web page to the wallet address&#xA;input field ?&#xA;&#xA;The clipboard is just a low-hanging fruit for malware, anyway. It just&#xA;the most easy point to replace an address. If the computer is&#xA;compromized, malware can edit the web page in the memory of the browser&#xA;process, for example. If it shown as QR code, malware can decode,&#xA;detect that it is an address, and replace the image of QR code.&#xA;&#xA;I think that the only way to protect from this is to add some form of&#xA;authentication for an address - 2fa (transfer checksum via second&#xA;channel), visual fingerprints for addresses, that will are hard to&#xA;detect (and hence, replace) for malware, signing the destination address&#xA;with the key of an address that is already known and checking the&#xA;signature, etc.&#xA;&#xA;The problem will be to come up with an address authentication procedure&#xA;that will be convenient for users and widely supported, as a result.</html></oembed>