<oembed><type>rich</type><version>1.0</version><author_name>npub1azvhdrf9fu6n0tm7yez4j6zcxcedp2ct6nrcq3z74naqs7kgpk8s5t2krq</author_name><author_url>https://nostr.ae/npub1azvhdrf9fu6n0tm7yez4j6zcxcedp2ct6nrcq3z74naqs7kgpk8s5t2krq</author_url><provider_name>njump</provider_name><provider_url>https://nostr.ae</provider_url><html>📅 Original date posted:2015-06-21&#xA;📝 Original message:&gt; On Jun 20, 2015, at 11:45 PM, Jeff Garzik &lt;jgarzik at bitpay.com&gt; wrote:&#xA;&gt; &#xA;&gt; On Sat, Jun 20, 2015 at 5:54 PM, Eric Lombrozo &lt;elombrozo at gmail.com &lt;mailto:elombrozo at gmail.com&gt;&gt; wrote:&#xA;&gt;  but we NEED to be applying some kind of pressure on the merchant end to upgrade their stuff to be more resilient&#xA;&gt; &#xA;&gt; Can you be specific?  What precise technical steps would you have BitPay and Coinbase do?  We upgrade our stuff to... what exactly?&#xA;&gt; &#xA;&gt; --&#xA;&gt; Jeff Garzik&#xA;&gt; Bitcoin core developer and open source evangelist&#xA;&gt; BitPay, Inc.      https://bitpay.com/ &lt;https://bitpay.com/&gt;&#xA;Thanks for asking *the* question, Jeff. We often get caught up in these philosophical debates…but at the end of the day we need something concrete.&#xA;&#xA;Even more important than the specific software you’re using is the security policy.&#xA;&#xA;If you must accept zero confirmation transactions, there are a few concrete things you can do to reduce your exposure:&#xA;&#xA;1) limit the transaction amounts for zero confirmation transactions - do not accept them for very high priced goods…especially if they require physical shipping.&#xA;2) limit the total amount of unconfirmed revenue you’ll tolerate at any given moment - if the amount is exceeded, require confirmations.&#xA;3) give merchants of subscription services (i.e. servers, hosting, etc…) the ability to shut the user out if a double-spend is detected.&#xA;4) collect legal information on purchasers (or have the merchants collect this information) so you have someone to go after if they try to screw you&#xA;5) create a risk profile for users…and flag suspicious behavior (i.e. someone trying to purchase a bunch of stuff that totally doesn’t fit into their purchasing habits).&#xA;6) get insurance (although right now reasonably-priced insurance is probably pretty hard to obtain since statistics are generally of little use…we’re entering uncharted territory).&#xA;7) set up a warning system and a “panic” button so that if you start to see an attack you can immediately disable all zero confirmation transactions system-wide.&#xA;8) independently verify all inbound transactions and connect to multiple network nodes…check them against one another.&#xA;&#xA;&#xA;As for software tools to accomplish these things, we can talk about that offline :)&#xA;&#xA;&#xA;- Eric Lombrozo&#xA;&#xA;&#xA;&#xA;&#xA;-------------- next part --------------&#xA;An HTML attachment was scrubbed...&#xA;URL: &lt;http://lists.linuxfoundation.org/pipermail/bitcoin-dev/attachments/20150621/95ab06d4/attachment.html&gt;&#xA;-------------- next part --------------&#xA;A non-text attachment was scrubbed...&#xA;Name: signature.asc&#xA;Type: application/pgp-signature&#xA;Size: 842 bytes&#xA;Desc: Message signed with OpenPGP using GPGMail&#xA;URL: &lt;http://lists.linuxfoundation.org/pipermail/bitcoin-dev/attachments/20150621/95ab06d4/attachment.sig&gt;</html></oembed>