Luke Dashjr [ARCHIVE] on Nostr: 📅 Original date posted:2016-08-16 📝 Original message:On Tuesday, August 16, ...
📅 Original date posted:2016-08-16
📝 Original message:On Tuesday, August 16, 2016 2:10:04 PM Jonas Schnelli via bitcoin-dev wrote:
> The BIP describes two approaches how to communicate (pipe and
> URI-scheme) with the signing-devices app, although, in my opinion, all
> major platform do support the URI approach (maybe we could drop the pipe
> approach then).
IMO it's kindof ugly to abuse URIs for communication. Stdio pipes are pretty
universally supported, why not just use those?
On the other hand, no matter how the plugin is implemented, it's still a
security risk, and requires installation (which the user might not have access
for). It would be best if the hardware protocol were standardised, so the user
doesn't need a plugin of *any* sort... I notice some hardware wallets have
begun to implement (or reuse) Trezor's interface, so that would seem a good
place to start?
Luke
Published at
2023-06-07 17:52:53Event JSON
{
"id": "a763067d031fa39ca8f7a3c1c5293e3b4f206caa1398de88916a3e73907d5ee5",
"pubkey": "5a6d1f44482b67b5b0d30cc1e829b66a251f0dc99448377dbe3c5e0faf6c3803",
"created_at": 1686160373,
"kind": 1,
"tags": [
[
"e",
"6e7f7cb2c3110cb7289a3abd667304a3b4e6f9ba4e2581c492d7b93c214a5ea1",
"",
"root"
],
[
"e",
"160405f5b06960b2e8dbeec7d221ab5b9be457d828a1882dc69917e5e0e980ca",
"",
"reply"
],
[
"p",
"cd7a2cba8fb58a6131210185f2257692f56b666fb24bf9cf016ca8aaa4a4ae01"
]
],
"content": "📅 Original date posted:2016-08-16\n📝 Original message:On Tuesday, August 16, 2016 2:10:04 PM Jonas Schnelli via bitcoin-dev wrote:\n\u003e The BIP describes two approaches how to communicate (pipe and\n\u003e URI-scheme) with the signing-devices app, although, in my opinion, all\n\u003e major platform do support the URI approach (maybe we could drop the pipe\n\u003e approach then).\n\nIMO it's kindof ugly to abuse URIs for communication. Stdio pipes are pretty \nuniversally supported, why not just use those?\n\nOn the other hand, no matter how the plugin is implemented, it's still a \nsecurity risk, and requires installation (which the user might not have access \nfor). It would be best if the hardware protocol were standardised, so the user \ndoesn't need a plugin of *any* sort... I notice some hardware wallets have \nbegun to implement (or reuse) Trezor's interface, so that would seem a good \nplace to start?\n\nLuke",
"sig": "da3e0b272ccaba28581581821a338bb4ade119a249773c387aee3385e2dcfcba4b820705f74322ea426bdcb3ac675b0bb645d38eff98093c40825dce7adce12d"
}