1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
|
Return-Path: <kanzure@gmail.com>
Received: from smtp4.osuosl.org (smtp4.osuosl.org [IPv6:2605:bc80:3010::137])
by lists.linuxfoundation.org (Postfix) with ESMTP id 3F7BBC002D
for <bitcoin-dev@lists.linuxfoundation.org>;
Tue, 18 Oct 2022 00:07:24 +0000 (UTC)
Received: from localhost (localhost [127.0.0.1])
by smtp4.osuosl.org (Postfix) with ESMTP id 17CBA4183F
for <bitcoin-dev@lists.linuxfoundation.org>;
Tue, 18 Oct 2022 00:07:24 +0000 (UTC)
DKIM-Filter: OpenDKIM Filter v2.11.0 smtp4.osuosl.org 17CBA4183F
Authentication-Results: smtp4.osuosl.org;
dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com
header.a=rsa-sha256 header.s=20210112 header.b=hLZuGkm5
X-Virus-Scanned: amavisd-new at osuosl.org
X-Spam-Flag: NO
X-Spam-Score: -2.098
X-Spam-Level:
X-Spam-Status: No, score=-2.098 tagged_above=-999 required=5
tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1,
DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, FREEMAIL_FROM=0.001,
HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001,
SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Received: from smtp4.osuosl.org ([127.0.0.1])
by localhost (smtp4.osuosl.org [127.0.0.1]) (amavisd-new, port 10024)
with ESMTP id ZezFK1gUNA5x
for <bitcoin-dev@lists.linuxfoundation.org>;
Tue, 18 Oct 2022 00:07:22 +0000 (UTC)
X-Greylist: whitelisted by SQLgrey-1.8.0
DKIM-Filter: OpenDKIM Filter v2.11.0 smtp4.osuosl.org B82994181D
Received: from mail-lf1-x12a.google.com (mail-lf1-x12a.google.com
[IPv6:2a00:1450:4864:20::12a])
by smtp4.osuosl.org (Postfix) with ESMTPS id B82994181D
for <bitcoin-dev@lists.linuxfoundation.org>;
Tue, 18 Oct 2022 00:07:21 +0000 (UTC)
Received: by mail-lf1-x12a.google.com with SMTP id o12so11599429lfq.9
for <bitcoin-dev@lists.linuxfoundation.org>;
Mon, 17 Oct 2022 17:07:21 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20210112;
h=to:subject:message-id:date:from:in-reply-to:references:mime-version
:from:to:cc:subject:date:message-id:reply-to;
bh=s+JYsP3jvk1cr5HVECuM07JcdkgeXjEP0zjv+oWm430=;
b=hLZuGkm5hX1Tl0P1MRXI5E0Eo9slVL4CIFXKBjeHtTvp/rahA2KUZMkUMeZE9EsYGc
HhiUvEEEowFaEkvuuNUkYu5nS5CSgajhTUNHNKXu3FSV3ZBr3FVWP3gUmMyltAFVSFvQ
AyE4xNXyQc6QE27RWSk5Q320f8huiK0nqW8XhwHQIHOrlVYnh0Rmff09vlaO0JHlO5kt
3n6c6vXHyygYnpF7hHd6LzY6wS+OZaN70nnPJc12uYfeZCSMHqArSWFN23TutGx44dEI
HDgIVLqSDMH5F+R033iVlrmTsWrEDqulMUQuYoPlspgkmlV8Q5E1U/Ip4XylC2BDpTLg
tUxQ==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
d=1e100.net; s=20210112;
h=to:subject:message-id:date:from:in-reply-to:references:mime-version
:x-gm-message-state:from:to:cc:subject:date:message-id:reply-to;
bh=s+JYsP3jvk1cr5HVECuM07JcdkgeXjEP0zjv+oWm430=;
b=KH1eVvcn6x1Mu6uK94EIxCzFJjDsIsXRzsJkYtCM0vpQx+svwmhoC/Du8Eo5ywnirm
OuXbOAj+32lqk6ts1Kj4xF1ZTdTcmO0grw9QKERjyGhusTXA7UZI6l8jNHTaVAw4lzfN
R1sDvJMqjepCcLDSDbVhJum7MpuP4TrObZ+5EPdZUcZN/q/6jlN2lNieJKkUTn/BtR6I
LyFDkduxSnD1IPs2Fst3dNL7SSi7mNPZuUVv9n+tTIn+VGCtVtcVOxRlzRXjs3pjrYsM
gyzX7phH0R400tEQ2tid3ZmyjQPxF4Pmqjn/AHl+03Jq1mrTKzLlwjhPDiVXrR1FaRXh
oKaQ==
X-Gm-Message-State: ACrzQf0/t2BxAyY7/be8tVtDqzRNa7dnBNEB53d3xYXJyIilx7Xs5ZyH
sMLtSSRJKlCKPTvnlVnseuprIRVsMM8R3DaIWb4=
X-Google-Smtp-Source: AMsMyM5aojDP7j9ABImo5OlhOiQ0FtlLom10xJzznu7EnWRGYECm7Qr7YuoyZimqRP1E4JKOFbTOS6F+ljUGXG1RhSQ=
X-Received: by 2002:a05:6512:208e:b0:4a2:3030:dc28 with SMTP id
t14-20020a056512208e00b004a23030dc28mr55941lfr.480.1666051639510; Mon, 17 Oct
2022 17:07:19 -0700 (PDT)
MIME-Version: 1.0
References: <CAPv7TjbOcH2mte8SWALc2o5aEKLO7qoZ-M_e1wHdGSp6EmMc2Q@mail.gmail.com>
<9f399e0c2713f2b1d2534cd754356bb5@dtrt.org>
<CAPv7TjY=35H2rmCxBavLwe3+8A9osao0QAMF_grb6WFA502b5Q@mail.gmail.com>
<1-euAstnYmNT7A9s0rniXdimmudFXODjkXiYXLK1hx1W7f_2rBLD1lPpaNi9Vx9tq2oahdCs6wDuXMy9SR6WfRTYzl2vDxSi6IVQLELKNLs=@protonmail.com>
In-Reply-To: <1-euAstnYmNT7A9s0rniXdimmudFXODjkXiYXLK1hx1W7f_2rBLD1lPpaNi9Vx9tq2oahdCs6wDuXMy9SR6WfRTYzl2vDxSi6IVQLELKNLs=@protonmail.com>
From: Bryan Bishop <kanzure@gmail.com>
Date: Mon, 17 Oct 2022 19:07:07 -0500
Message-ID: <CABaSBazV-ZO2kUEZzDubGQbxn-zt4acJ1wQxzJo9y4qFYtWM-w@mail.gmail.com>
To: rot13maxi <rot13maxi@protonmail.com>,
Bitcoin Protocol Discussion <bitcoin-dev@lists.linuxfoundation.org>,
Bryan Bishop <kanzure@gmail.com>
Content-Type: multipart/alternative; boundary="00000000000026901d05eb43e0fd"
Subject: Re: [bitcoin-dev]
=?utf-8?q?Trustless_Address_Server_=E2=80=93_Outsou?=
=?utf-8?q?rcing_handing_out_addresses_to_prevent_address_reuse?=
X-BeenThere: bitcoin-dev@lists.linuxfoundation.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Bitcoin Protocol Discussion <bitcoin-dev.lists.linuxfoundation.org>
List-Unsubscribe: <https://lists.linuxfoundation.org/mailman/options/bitcoin-dev>,
<mailto:bitcoin-dev-request@lists.linuxfoundation.org?subject=unsubscribe>
List-Archive: <http://lists.linuxfoundation.org/pipermail/bitcoin-dev/>
List-Post: <mailto:bitcoin-dev@lists.linuxfoundation.org>
List-Help: <mailto:bitcoin-dev-request@lists.linuxfoundation.org?subject=help>
List-Subscribe: <https://lists.linuxfoundation.org/mailman/listinfo/bitcoin-dev>,
<mailto:bitcoin-dev-request@lists.linuxfoundation.org?subject=subscribe>
X-List-Received-Date: Tue, 18 Oct 2022 00:07:24 -0000
--00000000000026901d05eb43e0fd
Content-Type: text/plain; charset="UTF-8"
On Mon, Oct 17, 2022 at 7:05 PM rot13maxi via bitcoin-dev <
bitcoin-dev@lists.linuxfoundation.org> wrote:
> Unbeknownst to them, the clipboard contents have been replaced with an
> address controlled by some bad actor.
>
[snip]
> Now imagine instead that the wallet has some address book with a pubkey
> for each recipient the user wants to send bitcoin to.
>
Isn't this the same problem but now for copy-pasting pubkeys instead of an
address?
- Bryan
https://twitter.com/kanzure
--00000000000026901d05eb43e0fd
Content-Type: text/html; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable
<div dir=3D"ltr"><div dir=3D"ltr">On Mon, Oct 17, 2022 at 7:05 PM rot13maxi=
via bitcoin-dev <<a href=3D"mailto:bitcoin-dev@lists.linuxfoundation.or=
g">bitcoin-dev@lists.linuxfoundation.org</a>> wrote:<br></div><div class=
=3D"gmail_quote"><blockquote class=3D"gmail_quote" style=3D"margin:0px 0px =
0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex"><div sty=
le=3D"font-family:Arial;font-size:14px">Unbeknownst to them, the clipboard =
contents have been replaced with an address controlled by some bad actor.<b=
r></div></blockquote><div>[snip]=C2=A0</div><blockquote class=3D"gmail_quot=
e" style=3D"margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204)=
;padding-left:1ex"><div style=3D"font-family:Arial;font-size:14px">Now imag=
ine instead that the wallet has some address book with a pubkey for each re=
cipient the user wants to send bitcoin to.<br></div></blockquote><div><br>I=
sn't this the same problem but now for copy-pasting pubkeys instead of =
an address?<br><br></div></div><div dir=3D"ltr" class=3D"gmail_signature"><=
div dir=3D"ltr">- Bryan<br><a href=3D"https://twitter.com/kanzure" target=
=3D"_blank">https://twitter.com/kanzure</a></div></div></div>
--00000000000026901d05eb43e0fd--
|