Payment Protocol for Face-to-face Payments



Summary:

The discussion is about how companies can obtain a Cert with their name via CAcert, but it requires some work to get assured as an organization. The conversation then shifts to the trustworthiness of CAs and whether users need to consider this. It is suggested that accepting only OS/browser built-in CAs may not be the best decision. The conversation then turns to the criticality of verifying the identity of a company when making a payment with Bitcoin online. It is noted that the company name on the certificate may differ from the name used by the customer, but that this is probably not a significant issue as it would be difficult for a virus or corrupt waiter to substitute a different name in a plausible manner. One solution proposed is to have a super-cheesy CA that issues certs with addresses in them, either by sending a postcard to the address or checking the ownership of the place on Google Maps for free. However, this approach may not work for vending machines.


Updated on: 2023-06-08T01:07:55.883017+00:00