Re: [Bitcoin-development] BIP70 extension to allow for identity delegation

2014-03-02 Thread Mike Hearn
On Sun, Mar 2, 2014 at 4:20 PM, Andreas Schildbach wrote: > I somehow think that it is too early for this heavy kind of extension, > given that the first version of BIP70 isn't even deployed widely let > alone *used*. > Definitely agree - like I said, I publish this only because I keep getting as

Re: [Bitcoin-development] BIP70 extension to allow for identity delegation

2014-03-02 Thread Andreas Schildbach
I somehow think that it is too early for this heavy kind of extension, given that the first version of BIP70 isn't even deployed widely let alone *used*. By reading your proposal I get the idea that the current spec doesn't allow two (or three) different PKIs at once -- we would want this for migr

Re: [Bitcoin-development] BIP70 extension to allow for identity delegation

2014-03-02 Thread Mike Hearn
On Sat, Mar 1, 2014 at 9:07 PM, Dev Random wrote: > I'm wondering about the small business case. A small business or an > individual might not have the technical expertise to perform the > delegation signature. If they take delivery of an SSL cert from the CA themselves, I don't see why it'd be

Re: [Bitcoin-development] BIP70 extension to allow for identity delegation

2014-03-02 Thread Mike Hearn
> > Perhaps the UI just isn't expressive enough currently to expose this > situation in any way, let alone reliably alert the user to the issue, > because there's no way for the payment processor to get authenticated > fields other than memo into the UI. > I think for now as long as payment proces

Re: [Bitcoin-development] BIP70 extension to allow for identity delegation

2014-03-02 Thread Jeremy Spilman
On Fri, 28 Feb 2014 03:46:49 -0800, Mike Hearn wrote:3) Whilst these payment processors currently verify merchants so the security risk is low, in future a lighter-weight model or competing sites that allow open signups would give a weak security situation: a hacker who compromised your computer

Re: [Bitcoin-development] BIP70 extension to allow for identity delegation

2014-03-01 Thread Kevin Greene
Another example use-case to back up devrandom's point is using a twitter handle as the "merchant name". In that example, a 3rd party service hosts and signs the PaymentRequest, but when someone opens that PaymentRequest in their wallet, they should know that they are paying the specified twitter us

[Bitcoin-development] BIP70 extension to allow for identity delegation

2014-02-28 Thread Mike Hearn
Now we're starting to see the first companies deploy BIP70, we're encountering a need for identity delegation. This need was long foreseen by the way: it's not in BIP70 because, well, we had to draw the line for v1 somewhere, and this is an issue that mostly affects payment processors. But I figure