Payment sender authentication



Summary:

In an email exchange between Joost Jager, fiatjaf, and peter, they discussed a temporary solution for providing identification information in BOLT11 payment requests. Fiatjaf suggested using the lnurl-rfc repository which allows for users to provide a lone pubkey, domain-specific pubkey along with a signature of a challenge provided by the receiver, or an unauthenticated name or email. These options are then committed inside the BOLT11 payment request using the 'h' tag. Joost Jager expressed concerns about privacy implications of using signatures in payment requests but fiatjaf clarified that there were no significant privacy implications for the signature method as the key used to sign is generated in a way that makes it specific to the DNS domain of the service being paid, making it difficult for anyone to relate that signature to anyone else.


Updated on: 2023-06-03T07:04:44.269615+00:00