On the other hand, it appears that they are using Coinbase. In that case I'm not sure Mozilla would have direct access to a wallet. Instead I imagine that Coinbase keeps track of their balance which is divided among Coinbase's wallets (sort of like a bank). I'm not too well versed however, so maybe someone else can clear this up.
A wallet owner is able to generate new addresses at any time, and generally does so in order to verify that a payment is coming in for a specific transaction. For example, a Bitcoin ATM operator wouldn't generate a payment address until a patron is standing at the kiosk. As soon as a transaction is verified, the machine would dispense whatever amount of money and future payments to that address would probably be ignored.
You are right that Mozilla probably isn't even operating a bitcoin wallet in this case. They are probably just getting USD from Coinbase.
Here's some Python code for creating addresses on Coinbase, if anyone is interested in how it works: https://github.com/StackMonkey/utter-va/blob/master/webapp/l...
That said, I don't think there is a way to get the private keys for these addresses so you can use them on your own wallet software. Not that you would want to, given Coinbase is currently holding (and aware) of said addresses keys.
Single address can be used as an output of many transactions. There is nothing preventing it in the protocol. More - it's a "natural" thing. Generation of address per transaction is a very convenient but not enforced by anything.
A Bitcoin address is just an identifier (cryptographic hash) of a public key in a keypair. For every transaction you do, you can create a new one. It's also possible to publish one publicly, as an address to anonymously send donations to, which can also make it easier for the public to track how many donations have gone to that address, but for most purposes, you create one per transaction, so you can keep track of how much has been spent in that transaction.
Any time you send Bitcoins, the way it works is that it sends the portion you specify to the given address, and generates a new keypair for yourself to send the change back to an address you control.
So, unless you just happen to leave a single address published publicly as your donation address, you don't have a permanent address. If you want to collect any additional information associated with a transaction; an email address to send thanks (or hit up for donations later), information to collect for tax purposes, etc, you just create a new keypair and thus new address for that transaction.
> No one has a single "permanent" Bitcoin address.
And then you finished with:
>So, unless you just happen to leave a single address published publicly as your donation address, you don't have a permanent address.
But there is nothing in the protocol or any of the default clients that gives anyone a distinguished "permanent address". So saying "I wish we knew Mozilla's permanent Bitcoin address" indicates that such a thing is expected, when in reality any one address that an entity has is a good as any other, and addresses are generally intended to be ephemeral and single use.
I understand the risks of how the address inputs and outputs as probabilistically tied to my identity. If I cared about those things I probably use stealth addresses and dark wallet or something.
If you're doing any kind of transactions in volume, it's much easier to just give each customer a unique address to send to, so you can verify that you've been paid when the right amount has been transferred to that address. That way you don't have any confusion of who has actually paid you if two people owe you similar amounts at the same time, and you see a transaction come in of that amount.
So yes, it's possible to pick one address as your "single permanent address", but it's not something that's expected or common.
Perhaps the documentation was improved. I don't know if it was in the original paper.
https://blog.mozilla.org/blog/2014/04/05/faq-on-ceo-resignat...
EDIT: Why the downvotes? The biggest Mozilla news of the year hinges on the issue of donation privacy/transparency. Seems extremely pertinent to me.