On Fri, Feb 28, 2014 at 10:26:39PM -0800, Jeremy Spilman wrote: > We currently have subtle positive feedback of a signed payment request in > the form of the green background. Unsigned requests simply show up without > the green background, as well as requests which provide a certificate but > have a missing or invalid signature.
Are we talking a third-party 'root certificate'? I don't quite see why a cryptographic currency that has the most widely deployed ECDSA public/private key infrastructure ever needs to use external certificates. That seems like a significant reduction in security to pretend that a 'signed' certificate is any good when it's pretty easy to buy a compromised cert, or just hack the server its on. If it's 'signed' by the ECDSA private key that you are sending the payment to, by all means, make it bright green. I mean if you want to make it expensive for small businesses to take secure payments, why don't you add a native 'signing fee' extension and have a (more) transparent market for the price of perceived security, or at least a compile time option so i can turn this nonsense off for my customers. -- ---------------------------------------------------------------------------- Troy Benjegerdes 'da hozer' ho...@hozed.org 7 elements earth::water::air::fire::mind::spirit::soul grid.coop Never pick a fight with someone who buys ink by the barrel, nor try buy a hacker who makes money by the megahash ------------------------------------------------------------------------------ Flow-based real-time traffic analytics software. Cisco certified tool. Monitor traffic, SLAs, QoS, Medianet, WAAS etc. with NetFlow Analyzer Customize your own dashboards, set traffic alerts and generate reports. Network behavioral analysis & security monitoring. All-in-one tool. http://pubads.g.doubleclick.net/gampad/clk?id=126839071&iu=/4140/ostg.clktrk _______________________________________________ Bitcoin-development mailing list Bitcoin-development@lists.sourceforge.net https://lists.sourceforge.net/lists/listinfo/bitcoin-development