Out of interest, what is the security benefit of only showing our bitcoin
address if the user is viewing the website using HTTPS?

Seems pointless to me, since:

   1. The bitcoin address is not a secret
   2. If someone can do a MITM on the HTTP request, then they can edit the
   message that tells people to switch to HTTPS, and replace it with their own
   bitcoin address

Ian.

-- 
Ian Clarke
Founder, The Freenet Project
Email: ian at freenetproject.org
-------------- next part --------------
An HTML attachment was scrubbed...
URL: 
<https://emu.freenetproject.org/pipermail/devl/attachments/20110322/7d6a9847/attachment.html>

Reply via email to