247 karma · joined August 16, 2012
Segwit never getting activated may even be a good thing. It will show everyone that Bitcoin has crystalized and can never be changed via petty human emotion. This was always Bitcoin's true selling point and we may be about to demonstrate it.
So yes, politics can and will be ignored.
And said that "Segwit doesn't deliver that".
Segwit delivers that.
Of course that's not really what people bitching about tx fees want.
https://ripple.com/wiki/Consensus - http://bitcoin.stackexchange.com/questions/10180/what-are-th... - http://bitcoin.stackexchange.com/questions/13330/what-is-the...
RFC 3526 puts the low end of the 1536 bit group's strength at 90 bits. If some unknown weakness was found that lowers that significantly that doesn't leave things very safe.
Agreed that curves would be ideal.
In 2004 this was probably a fine choice, especially considering the tradeoff between CPU processing (usability) and security. But considering the NSA scandal, specifically them recording all encrypted communications forever, and Bruce Schneier increasing his key lengths [3], and the ability for CPUs to process higher keylengths without any noticeable slowdown, I don't feel confident it is strong enough today.
Other than this gripe OTR is amazing and everyone should be using it.
Edit: xnyhps's post [4] concludes that only a single "cracking" of the 1536 bit group would need to occur to then decrypt any past or future OTR conversation "instantly".
[1] https://web.archive.org/web/20041215062523/http://www.cypher... [2] http://www.ietf.org/rfc/rfc3526.txt [3] https://news.ycombinator.com/item?id=6376954 [4] https://blog.thijsalkema.de/blog/2014/01/17/misconceptions-a...
http://tools.ietf.org/html/rfc4492#appendix-A or list all openssl curves: $ openssl ecparam -list_curves
Here's one of the risks you have to bear to enable your chargebacks: http://mashable.com/2011/01/28/identity-theft-infographic/ ... worth it? Think how many insecure databases your name and address and credit card # (and sometimes phone number) are stored in across the net...
And if I _do_ have my own payment processing then I won't need to "transition to a different solution within six months". What does that mean, are they going to give me all the subscribers credit card info so I can start charging their cards myself? I don't think so.
As far as I know Braintree only does direct credit card processing, similar to Stripe. If they are planning on migrating all the Google Checkout subscriptions to Braintree credit card subscriptions that would be great but it doesn't sound like that to me. And how would that work for the Google Checkout users who were able to manage their subscriptions through the Google Checkout interface? Does Braintree have an interface for all Google Checkout users or do they lose their interface and need to go through the merchant now?
Edit: gavin has a plan (http://gavintech.blogspot.com/2012/05/neutralizing-51-attack...) but my guess is if they did the work to start an attack in the first place they'd have planned for gavin's plan and acquired enough older coins to foil it. It'd be nice if more thought went into other ways to thwart a possible attack but I'm not sure there really are any. Most people seem to discount and completely avoid the issue.