Conversation Details on Nostr: 📝 Summary: Dan Gould pointed out a flaw in the security protocol for Payjoin PSBT, ...
📝 Summary: Dan Gould pointed out a flaw in the security protocol for Payjoin PSBT, which has been fixed in the draft. The sender suggested using DH for sharing the secret key, but the author opted for a symmetric key. The author proposed a solution using ephemeral keys to mitigate the attack. symphonicbtc suggested using base64url instead of base64 encoding for improved readability and security. Christopher Allen recommended using base64url for the psk in the URI and UR encoding for displaying via QR codes.
👥 Authors:
• Dan Gould ( Dan Gould [ARCHIVE] (npub1l58…xs5k) )
• Christopher Allen ( Christopher Allen [ARCHIVE] (npub19g4…t5d0) )
• symphonicbtc ( symphonicbtc [ARCHIVE] (npub1tzu…45mf) )
📅 Messages Date: 2023-08-11
✉️ Message Count: 3
📚 Total Characters in Messages: 72896
Messages Summaries
✉️ Message by Dan Gould on 11/08/2023:
The sender pointed out a flaw in the protocol regarding the security of the Payjoin PSBT. The issue has been fixed in the draft. The sender also suggested using DH for securely sharing the secret key, but the author chose to use a symmetric key for convenience. The author proposed a solution to mitigate the attack by using ephemeral keys.
✉️ Message by symphonicbtc on 11/08/2023:
The sender suggests using base64url instead of base64 encoding for the psk in the URI to improve readability and security.
✉️ Message by Christopher Allen on 12/08/2023:
The author suggests using base64url instead of base64 encoding for the psk in the URI, and recommends UR encoding for displaying via QR codes.
Follow Bitcoin Mailing List (npub15g7…08lk) for full threads
Published at
2023-08-12 09:56:45Event JSON
{
"id": "a11c70687ddab3a317ae96946a8ab8920214832586180014dea9a2aa7ca3c504",
"pubkey": "57fe4c4ae74215fb92bd0dcb8a7787c5e907db74e987f30f1acaaad9c3a0271f",
"created_at": 1691834205,
"kind": 30023,
"tags": [
[
"d",
"ed757caa-bd4f-4811-9518-50e8562d2c1d"
],
[
"title",
"Conversation Details"
],
[
"image",
"https://nostr.build/i/dbc5bd7993c8d036431edeefea63a2b3b796e1f49baf96bf6b09e13c8c662833.jpg"
],
[
"p",
"fd0ebd1f355c5c85b3b4ccf8c1d7bd31bfc5fa039dcc73f5892258aa4857b65a"
],
[
"p",
"2a2be7532ec03e16fa6ff38360d30cc714893870cbd9fafbefeb1df2df858c4d"
],
[
"p",
"58b97713abc0e7cc1096f3d69a02d15a0b357385a84c02fab5c8732e70404d06"
],
[
"p",
"a23dbf6c6cc83e14cc3df4e56cc71845f611908084cfe620e83e40c06ccdd3d0"
]
],
"content": "📝 Summary: Dan Gould pointed out a flaw in the security protocol for Payjoin PSBT, which has been fixed in the draft. The sender suggested using DH for sharing the secret key, but the author opted for a symmetric key. The author proposed a solution using ephemeral keys to mitigate the attack. symphonicbtc suggested using base64url instead of base64 encoding for improved readability and security. Christopher Allen recommended using base64url for the psk in the URI and UR encoding for displaying via QR codes.\n\n👥 Authors: \n• Dan Gould ( nostr:npub1l58t68e4t3wgtva5enuvr4aaxxlut7srnhx88avfyfv25jzhkedq6nxs5k )\n• Christopher Allen ( nostr:npub19g47w5ewcqlpd7n07wpkp5cvcu2gjwrse0vl47l0avwl9hu933xsqct5d0 )\n• symphonicbtc ( nostr:npub1tzuhwyatcrnucyyk70tf5qk3tg9n2uu94pxq9744epejuuzqf5rqw445mf )\n\n📅 Messages Date: 2023-08-11\n\n✉️ Message Count: 3\n\n📚 Total Characters in Messages: 72896\n\n## Messages Summaries\n\n✉️ Message by Dan Gould on 11/08/2023:\nThe sender pointed out a flaw in the protocol regarding the security of the Payjoin PSBT. The issue has been fixed in the draft. The sender also suggested using DH for securely sharing the secret key, but the author chose to use a symmetric key for convenience. The author proposed a solution to mitigate the attack by using ephemeral keys.\n\n✉️ Message by symphonicbtc on 11/08/2023:\nThe sender suggests using base64url instead of base64 encoding for the psk in the URI to improve readability and security.\n\n✉️ Message by Christopher Allen on 12/08/2023:\nThe author suggests using base64url instead of base64 encoding for the psk in the URI, and recommends UR encoding for displaying via QR codes.\n\n\nFollow nostr:npub15g7m7mrveqlpfnpa7njke3ccghmpryyqsn87vg8g8eqvqmxd60gqmx08lk for full threads",
"sig": "d3c21267d2e2d978a5c0afdf285ef98e2c2ef30e044a89f52a47c975380c6fa79d2deb1c29a675ca943d05e034da48d8801986ec2be3ef47c064bd50a12c45cc"
}